2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2004-0728——The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to ...
CVE-2004-0729——PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.ph...
CVE-2004-0730——Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script...
CVE-2004-0719——Internet Explorer for Mac 5.2.3, Internet Explorer 6 on Windows XP, and possibly other versions, does not properly preve...
CVE-2004-0720——Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another...
CVE-2004-0721——Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting conte...
CVE-2004-0723——Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write c...
CVE-2004-0725——Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbit...
CVE-2004-0695——Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbit...
CVE-2004-0736——The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search p...
CVE-2004-0705——Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cg...
CVE-2004-0735——Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe...
CVE-2004-0706——Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password i...
CVE-2004-0707——SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote at...
CVE-2004-0708——MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existi...
CVE-2004-0709——HP OpenView Select Access 5.0 through 6.0 does not correctly decode UTF-8 encoded unicode characters in a URL, which cou...
CVE-2004-0734——Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
CVE-2004-0733——Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly ex...
CVE-2004-0710——IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers ...
CVE-2004-0711——The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if th...
CVE-2004-0712——The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 creat...
CVE-2004-0713——The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 throug...
CVE-2004-0714——Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ...
CVE-2004-0715——The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 do...
CVE-2004-0717——Opera 7.51 for Windows and 7.50 for Linux does not properly prevent a frame in one domain from injecting content into a ...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now