2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1630Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attacke...
CVE-2004-1633process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field,...
CVE-2004-1631Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the tar...
CVE-2004-1632Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arb...
CVE-2004-1635Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect pr...
CVE-2004-1629Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL s...
CVE-2004-1628Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.
CVE-2004-1626Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code v...
CVE-2004-1623The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in E...
CVE-2004-1625pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows re...
CVE-2004-1627Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbi...
CVE-2004-1620CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting att...
CVE-2004-1622SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statem...
CVE-2004-1624Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, wh...
CVE-2004-0746Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd....
CVE-2004-0754Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary...
CVE-2004-1381Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the acti...
CVE-2004-1380Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow re...
CVE-2004-0755The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permiss...
CVE-2004-0559The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a ...
CVE-2004-0053Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME ...
CVE-2004-1619Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickn...
CVE-2004-0778CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary fil...
CVE-2004-0777Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when l...
CVE-2004-0775Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2....

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now