2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-0648 | — | — | 5.3% | Aug 6, 2004 | Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitr... |
| CVE-2004-0582 | — | — | 2.1% | Aug 6, 2004 | Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to con... |
| CVE-2004-0554 | — | — | 0.9% | Aug 6, 2004 | Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an inf... |
| CVE-2004-0493 | — | — | 84.8% | Aug 6, 2004 | The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memor... |
| CVE-2004-0583 | — | — | 2.1% | Aug 6, 2004 | The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, wh... |
| CVE-2004-0413 | — | — | 5.9% | Aug 6, 2004 | libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL ... |
| CVE-2004-0414 | — | — | 4.0% | Aug 6, 2004 | CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents ... |
| CVE-2004-0416 | — | — | 13.2% | Aug 6, 2004 | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may a... |
| CVE-2004-0584 | — | — | 1.3% | Aug 6, 2004 | Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which a... |
| CVE-2004-0585 | — | — | — | Aug 6, 2004 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0589. Reason: This candidate is a duplicate of... |
| CVE-2004-0586 | — | — | 4.2% | Aug 6, 2004 | acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, a... |
| CVE-2004-0587 | — | — | 0.4% | Aug 6, 2004 | Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service... |
| CVE-2004-1710 | — | — | 2.1% | Aug 6, 2004 | page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter. |
| CVE-2004-0588 | — | — | 1.4% | Aug 6, 2004 | Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbi... |
| CVE-2004-0417 | — | — | 3.1% | Aug 6, 2004 | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x t... |
| CVE-2004-0589 | — | — | 3.0% | Aug 6, 2004 | Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers ... |
| CVE-2004-0536 | — | — | 0.4% | Aug 6, 2004 | Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, ... |
| CVE-2004-0535 | — | — | 0.5% | Aug 6, 2004 | The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows l... |
| CVE-2004-0530 | — | — | 0.4% | Aug 6, 2004 | The PHP package in Slackware 8.1, 9.0, and 9.1, when linked against a static library, includes /tmp in the search path, ... |
| CVE-2004-0557 | — | — | 25.1% | Aug 6, 2004 | Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allo... |
| CVE-2004-0529 | — | — | 1.5% | Aug 6, 2004 | The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mo... |
| CVE-2004-0672 | — | — | 2.0% | Aug 6, 2004 | Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMi... |
| CVE-2004-0528 | — | — | 2.3% | Aug 6, 2004 | Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified... |
| CVE-2004-0527 | — | — | 5.8% | Aug 6, 2004 | KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with m... |
| CVE-2004-0526 | — | — | 17.2% | Aug 6, 2004 | Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now