2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-1371——Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in t...
CVE-2004-1368——ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname i...
CVE-2004-1708——Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.
CVE-2004-1706——The U.S. Robotics USR808054 wireless access point allows remote attackers to cause a denial of service (device crash) an...
CVE-2004-1705——Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
CVE-2004-1704——WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the ...
CVE-2004-1703HIGH8.8Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that co...
CVE-2004-1707——The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default pa...
CVE-2004-2066——SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and byp...
CVE-2004-2067——SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attack...
CVE-2004-2064——Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web scr...
CVE-2004-0709——HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which cou...
CVE-2004-0710——IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers ...
CVE-2004-0711——The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if th...
CVE-2004-0632——Adobe Reader 6.0 does not properly handle null characters when splitting a filename path into components, which allows r...
CVE-2004-0712——The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 creat...
CVE-2004-0713——The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 throug...
CVE-2004-0714——Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ...
CVE-2004-0715——The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 do...
CVE-2004-0735——Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe...
CVE-2004-0736——The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search p...
CVE-2004-0717——Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a ...
CVE-2004-0737——Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to ...
CVE-2004-0718——The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a fram...
CVE-2004-2061CRITICAL9.8RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbi...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now