2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-0782——Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gd...
CVE-2004-0781——Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earl...
CVE-2004-0778——CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary fil...
CVE-2004-0777——Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when l...
CVE-2004-0772CRITICAL9.8Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remo...
CVE-2004-1353——Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to...
CVE-2004-1618——Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malforme...
CVE-2004-1613——Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) ...
CVE-2004-1614——Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unus...
CVE-2004-1615——Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web pa...
CVE-2004-1608——SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id par...
CVE-2004-1607——slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment...
CVE-2004-1621——NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Do...
CVE-2004-1612——Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)...
CVE-2004-1616——Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contai...
CVE-2004-1609——SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which ...
CVE-2004-1610——SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users t...
CVE-2004-1611——SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remo...
CVE-2004-1606——slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP r...
CVE-2004-1617——Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a...
CVE-2004-1603MEDIUM5.5cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature ...
CVE-2004-1601——Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files a...
CVE-2004-1599——Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary...
CVE-2004-1638——Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (...
CVE-2004-1600——index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now