2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1634——show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a b...
CVE-2004-1630——Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attacke...
CVE-2004-1631——Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the tar...
CVE-2004-1633——process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field,...
CVE-2004-1635——Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect pr...
CVE-2004-1629——Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL s...
CVE-2004-1628——Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.
CVE-2004-1623——The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in E...
CVE-2004-1625——pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows re...
CVE-2004-1626——Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code v...
CVE-2004-1627——Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbi...
CVE-2004-1620——CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting att...
CVE-2004-1624——Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, wh...
CVE-2004-1622——SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statem...
CVE-2004-0775——Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2....
CVE-2004-0768——libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execu...
CVE-2004-0755——The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permiss...
CVE-2004-0754——Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary...
CVE-2004-0753——The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a deni...
CVE-2004-0752——OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow loc...
CVE-2004-0751——The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows...
CVE-2004-0750——Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorr...
CVE-2004-0748——mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting ...
CVE-2004-0747HIGH7.8Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that caus...
CVE-2004-0746——Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd....

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now