2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-0125 | — | — | 0.3% | Aug 6, 2004 | The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables ori... |
| CVE-2004-0596 | — | — | 0.4% | Aug 6, 2004 | The Equalizer Load-balancer for serial network interfaces (eql.c) in Linux kernel 2.6.x up to 2.6.7 allows local users t... |
| CVE-2004-0591 | — | — | 5.0% | Aug 6, 2004 | Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3... |
| CVE-2004-0589 | — | — | 3.0% | Aug 6, 2004 | Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers ... |
| CVE-2004-0588 | — | — | 1.4% | Aug 6, 2004 | Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbi... |
| CVE-2004-0587 | — | — | 0.4% | Aug 6, 2004 | Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service... |
| CVE-2004-0586 | — | — | 4.2% | Aug 6, 2004 | acpRunner ActiveX 1.2.5.0 allows remote attackers to execute arbitrary code via the (1) DownLoadURL, (2) SaveFilePath, a... |
| CVE-2004-0585 | — | — | — | Aug 6, 2004 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0589. Reason: This candidate is a duplicate of... |
| CVE-2004-0584 | — | — | 1.3% | Aug 6, 2004 | Unknown vulnerability in Horde IMP 3.2.3 and earlier, before a "security fix," does not properly validate input, which a... |
| CVE-2004-0583 | — | — | 2.1% | Aug 6, 2004 | The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, wh... |
| CVE-2004-0582 | — | — | 2.1% | Aug 6, 2004 | Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to con... |
| CVE-2004-0581 | — | — | 0.4% | Aug 6, 2004 | ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrar... |
| CVE-2004-0580 | — | — | 8.0% | Aug 6, 2004 | DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly cl... |
| CVE-2004-0579 | — | — | 0.4% | Aug 6, 2004 | Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root. |
| CVE-2004-0641 | — | — | 2.6% | Aug 5, 2004 | Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP I... |
| CVE-2004-1364 | — | — | 13.8% | Aug 4, 2004 | Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries ... |
| CVE-2004-1367 | — | — | 7.3% | Aug 4, 2004 | Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP o... |
| CVE-2004-1366 | — | — | 15.5% | Aug 4, 2004 | Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.propertie... |
| CVE-2004-1369 | — | — | 5.6% | Aug 4, 2004 | The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed ser... |
| CVE-2004-1365 | — | — | 7.4% | Aug 4, 2004 | Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local... |
| CVE-2004-1709 | — | — | 0.3% | Aug 4, 2004 | Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token... |
| CVE-2004-1679 | — | — | 1.7% | Aug 4, 2004 | Directory traversal vulnerability in TwinFTP 1.0.3 R2 allows remote attackers to create arbitrary files via a .../ (trip... |
| CVE-2004-1362 | — | — | 9.0% | Aug 4, 2004 | The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set... |
| CVE-2004-1363 | CRITICAL | 9.8 | 9.1% | Aug 4, 2004 | Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in ... |
| CVE-2004-1370 | — | — | 3.9% | Aug 4, 2004 | Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remo... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now