2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-0343Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL v...
CVE-2004-0342MEDIUM5.5WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service ...
CVE-2004-0341WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local us...
CVE-2004-0340Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Se...
CVE-2004-0339Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers...
CVE-2004-0338SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL quer...
CVE-2004-0337Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary scrip...
CVE-2004-0336LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains ...
CVE-2004-0335LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a ...
CVE-2004-1331The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Sec...
CVE-2004-1315viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase...
CVE-2004-0885The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location c...
CVE-2004-0832The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled...
CVE-2004-0206Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and ...
CVE-2004-0847CRITICAL9.8The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .asp...
CVE-2004-0828The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before execu...
CVE-2004-0938FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Se...
CVE-2004-0835MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights o...
CVE-2004-0209Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Serv...
CVE-2004-0846Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute ar...
CVE-2004-0845Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain informat...
CVE-2004-0844Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars ...
CVE-2004-0910Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0815. Reason: This candidate is a reservation ...
CVE-2004-0214Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me ...
CVE-2004-0920Symantec Norton AntiVirus 2004, and earlier versions, allows a virus or other malicious code to avoid detection or cause...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now