2004 CVE Vulnerabilities
2,707 CVEs published in 2004.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2004-0401 | — | — | 2.0% | Jul 7, 2004 | Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions. |
| CVE-2004-0400 | — | — | 7.0% | Jul 7, 2004 | Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attack... |
| CVE-2004-0399 | — | — | 20.5% | Jul 7, 2004 | Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows rem... |
| CVE-2004-0398 | — | — | 5.0% | Jul 7, 2004 | Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earli... |
| CVE-2004-0397 | — | — | 75.3% | Jul 7, 2004 | Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attacker... |
| CVE-2004-1345 | — | — | 0.4% | Jun 21, 2004 | Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local user... |
| CVE-2004-1346 | — | — | 0.4% | Jun 19, 2004 | The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a m... |
| CVE-2004-1754 | — | — | 2.5% | Jun 15, 2004 | The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via... |
| CVE-2004-0396 | — | — | 67.5% | Jun 14, 2004 | Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows... |
| CVE-2004-0392 | — | — | 2.5% | Jun 14, 2004 | racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via... |
| CVE-2004-0199 | — | — | 26.1% | Jun 14, 2004 | Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which a... |
| CVE-2004-0050 | — | — | 1.4% | Jun 14, 2004 | Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS dev... |
| CVE-2004-0038 | — | — | 3.2% | Jun 14, 2004 | McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary comma... |
| CVE-2004-0227 | — | — | 3.2% | Jun 14, 2004 | Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via ... |
| CVE-2004-0154 | — | — | 1.7% | Jun 14, 2004 | rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mo... |
| CVE-2004-0389 | HIGH | 7.5 | 52.5% | Jun 1, 2004 | RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via mal... |
| CVE-2004-0157 | — | — | 0.4% | Jun 1, 2004 | x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows lo... |
| CVE-2004-0181 | — | — | 0.4% | Jun 1, 2004 | The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the... |
| CVE-2004-0156 | — | — | 3.5% | Jun 1, 2004 | Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays... |
| CVE-2004-0155 | — | — | 3.6% | Jun 1, 2004 | The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not veri... |
| CVE-2004-0409 | — | — | 9.0% | Jun 1, 2004 | Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows re... |
| CVE-2004-0177 | — | — | 2.6% | Jun 1, 2004 | The ext3 code in Linux 2.4.x before 2.4.26 does not properly initialize journal descriptor blocks, which causes an infor... |
| CVE-2004-0407 | — | — | 1.5% | Jun 1, 2004 | The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allo... |
| CVE-2004-0178 | — | — | 0.4% | Jun 1, 2004 | The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not p... |
| CVE-2004-0179 | — | — | 11.1% | Jun 1, 2004 | Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Ca... |
Check if your code is affected by 2004 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now