2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2004-2064——Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web scr...
CVE-2004-2067——SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attack...
CVE-2004-0696——The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a ...
CVE-2004-0594——The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when reg...
CVE-2004-0595——The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag ...
CVE-2004-0600——Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute a...
CVE-2004-0632——Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows r...
CVE-2004-0686——Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb....
CVE-2004-0566——Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a...
CVE-2004-0742——Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privile...
CVE-2004-0741——LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long...
CVE-2004-0740——The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server c...
CVE-2004-0739——Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and po...
CVE-2004-0738——Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL ...
CVE-2004-0737——Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to ...
CVE-2004-0697——Unknown vulnerability in 4D WebSTAR 5.3.2 and earlier allows remote attackers to read the php.ini configuration file and...
CVE-2004-0698——4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.
CVE-2004-0700——Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Ap...
CVE-2004-0701——Sun Ray Server Software (SRSS) 1.3 and 2.0 for Solaris 2.6, 7 and 8 does not properly detect a smartcard removal when th...
CVE-2004-0702——DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not runn...
CVE-2004-0703——Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membersh...
CVE-2004-0704——Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, w...
CVE-2004-0724——The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) vi...
CVE-2004-0726——The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the lo...
CVE-2004-0727——Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now