2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2004-0648——Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitr...
CVE-2004-0582——Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to con...
CVE-2004-0554——Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an inf...
CVE-2004-0493——The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memor...
CVE-2004-0583——The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, wh...
CVE-2004-0413——libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL ...
CVE-2004-0414——CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents ...
CVE-2004-0416——Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may a...
CVE-2004-0584——Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which a...
CVE-2004-0585——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0589. Reason: This candidate is a duplicate of...
CVE-2004-0586——acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, a...
CVE-2004-0587——Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service...
CVE-2004-1710——page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.
CVE-2004-0588——Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbi...
CVE-2004-0417——Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x t...
CVE-2004-0589——Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers ...
CVE-2004-0536——Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, ...
CVE-2004-0535——The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows l...
CVE-2004-0530——The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, ...
CVE-2004-0557——Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allo...
CVE-2004-0529——The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mo...
CVE-2004-0672——Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMi...
CVE-2004-0528——Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified...
CVE-2004-0527——KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with m...
CVE-2004-0526——Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now