2004 CVE Vulnerabilities

2,707 CVEs published in 2004.

CVE IDSeverityCVSSDescription
CVE-2004-0566——Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a...
CVE-2004-0725——Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbit...
CVE-2004-0727——Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows...
CVE-2004-0728——The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to ...
CVE-2004-0703——Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membersh...
CVE-2004-0704——Unknown vulnerability in (1) duplicates.cgi and (2) buglist.cgi in Bugzilla 2.16.x before 2.16.6, 2.18 before 2.18rc1, w...
CVE-2004-0729——PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.ph...
CVE-2004-0730——Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script...
CVE-2004-0731——Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to injec...
CVE-2004-0600——Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute a...
CVE-2004-0739——Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and po...
CVE-2004-0595——The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag ...
CVE-2004-0594——The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when reg...
CVE-2004-0732——SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary ...
CVE-2004-0733——Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly ex...
CVE-2004-0740——The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server c...
CVE-2004-0705——Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cg...
CVE-2004-0706——Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password i...
CVE-2004-0741——LionMax Software WWW File Share Pro 2.60 allows remote attackers to cause a denial of service (crash or hang) via a long...
CVE-2004-0742——Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privile...
CVE-2004-0707——SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote at...
CVE-2004-0734——Web_Store.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
CVE-2004-0708——MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existi...
CVE-2004-0720——Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another...
CVE-2004-0721——Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting conte...

Check if your code is affected by 2004 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now