2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-0349 | — | — | 3.2% | Nov 23, 2004 | Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot ... |
| CVE-2004-0350 | — | — | 0.5% | Nov 23, 2004 | SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local user... |
| CVE-2004-0351 | — | — | 0.5% | Nov 23, 2004 | Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local u... |
| CVE-2004-0494 | — | — | 1.6% | Nov 23, 2004 | Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform ce... |
| CVE-2004-0352 | — | — | 3.2% | Nov 23, 2004 | Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02... |
| CVE-2004-0353 | — | — | 4.7% | Nov 23, 2004 | Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow... |
| CVE-2004-0354 | — | — | 15.6% | Nov 23, 2004 | Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to ex... |
| CVE-2004-0355 | — | — | 1.7% | Nov 23, 2004 | Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal P... |
| CVE-2004-0356 | — | — | 7.5% | Nov 23, 2004 | Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to exec... |
| CVE-2004-1331 | — | — | 19.5% | Nov 16, 2004 | The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Sec... |
| CVE-2004-1315 | — | — | 71.9% | Nov 12, 2004 | viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase... |
| CVE-2004-0815 | — | — | 4.9% | Nov 3, 2004 | The unix_clean_name function in Samba 2.2.x through 2.2.11, and 3.0.x before 3.0.2a, trims certain directory names down ... |
| CVE-2004-0552 | — | — | 23.9% | Nov 3, 2004 | Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device na... |
| CVE-2004-0569 | — | — | 19.4% | Nov 3, 2004 | The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of ... |
| CVE-2004-0572 | — | — | 50.0% | Nov 3, 2004 | Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary cod... |
| CVE-2004-0574 | — | — | 67.8% | Nov 3, 2004 | The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Ser... |
| CVE-2004-0575 | — | — | 60.3% | Nov 3, 2004 | Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows S... |
| CVE-2004-0774 | — | — | 1.9% | Nov 3, 2004 | RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of s... |
| CVE-2004-0804 | — | — | 4.3% | Nov 3, 2004 | Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via ... |
| CVE-2004-0828 | — | — | 0.3% | Nov 3, 2004 | The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before execu... |
| CVE-2004-0832 | — | — | 10.7% | Nov 3, 2004 | The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled... |
| CVE-2004-0835 | — | — | 22.4% | Nov 3, 2004 | MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights o... |
| CVE-2004-0836 | — | — | 9.8% | Nov 3, 2004 | Buffer overflow in the mysql_real_connect function in MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows remote DNS... |
| CVE-2004-0837 | — | — | 4.9% | Nov 3, 2004 | MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multi... |
| CVE-2004-0840 | — | — | 30.3% | Nov 3, 2004 | The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows ... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now