2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-0672——Multiple cross-site scripting (XSS) vulnerabilities in the primary and management web interfaces in Netegrity IdentityMi...
CVE-2004-1710——page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.
CVE-2004-0671——Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying t...
CVE-2004-1711——Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary we...
CVE-2004-1712——Cross-site scripting (XSS) vulnerability in TypePad allows remote attackers to inject arbitrary Javascript via the name ...
CVE-2004-0670——Prestige 650HW-31 running Rompager 4.7 software allows remote attackers to cause a denial of service (device reboot) via...
CVE-2004-0669——Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IM...
CVE-2004-0668——Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail ...
CVE-2004-0210HIGH7.8The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain pa...
CVE-2004-0205——Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the ...
CVE-2004-0416——Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may a...
CVE-2004-0417——Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x t...
CVE-2004-0461——The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnp...
CVE-2004-0460——Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote...
CVE-2004-0413——libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL ...
CVE-2004-0453——Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denia...
CVE-2004-0450——Format string vulnerability in the printlog function in log2mail before 0.2.5.2 allows local users or remote attackers t...
CVE-2004-0418——serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which ...
CVE-2004-0447——Unknown vulnerability in Linux before 2.4.26 for IA64 allows local users to cause a denial of service, with unknown impa...
CVE-2004-0667——Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to sys_creat, sys_open, and sys_mknod inside jai...
CVE-2004-0666——Off-by-one error in the POP3_readmsg function in popclient 3.0b6 allows remote attackers to cause a denial of service (a...
CVE-2004-0665——csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveal...
CVE-2004-0664——Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directorie...
CVE-2004-0663——Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary s...
CVE-2004-0662——PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now