CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2004-9999

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate has been used as a placeholder by multiple organizations for multiple issues, but it is invalid. Notes: All CVE users should search CVE for the proper identifier. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2004
    5.8
    Medium

    CVE-2004-2733

    Last Modified: 16 Apr 2026

    Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topics via pop_up_topic_admin.asp.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2747

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which triggers different error messages depending on whether the file exists or not.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2741

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) module, (2) topic, or (3) module parameters.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2647

    Last Modified: 16 Apr 2026

    Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2654

    Last Modified: 16 Apr 2026

    The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that the issue was a buffer overflow that was not fixed in STABLE6. However, the vendor's bug report clearly shows that the researcher later retracted this claim, because the tested product was actually STABLE5.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2656

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl.

    Published: 31 Dec 2004
    5.8
    Medium

    CVE-2004-2682

    Last Modified: 16 Apr 2026

    PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal), a related issue to CVE-2003-0147.

    Published: 31 Dec 2004
    8.5
    High

    CVE-2004-2690

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files.

    Published: 31 Dec 2004
    6.9
    Medium

    CVE-2004-2698

    Last Modified: 16 Apr 2026

    Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) and possibly modify arbitrary files via a symlink attack on the imwheel.pid file.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2706

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2710

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) sending certain typing statuses or (2) setting the chat room status bar to the current chat room name.

    Published: 31 Dec 2004
    1.9
    Low

    CVE-2004-2713

    Last Modified: 16 Apr 2026

    Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\* to the EVERYONE group, which allows local users to cause a denial of service by modifying the folder contents or permissions. NOTE: this issue has been disputed by the vendor, who claims that it does not affect product functionality since the same information is also saved in a protected file

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2732

    Last Modified: 16 Apr 2026

    nbmember.cgi in Netbilling 2.0 allows remote attackers to obtain sensitive information via the cmd=test option, which can be leveraged to determine the access key.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2740

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP code via a URL in the path_pre parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2646

    Last Modified: 16 Apr 2026

    The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2637

    Last Modified: 16 Apr 2026

    The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2260

    Last Modified: 16 Apr 2026

    Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2261

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in e107 allows remote attackers to inject arbitrary script or HTML via the "login name/author" field in the (1) news submit or (2) article submit functions.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2262

    Last Modified: 16 Apr 2026

    ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to execute arbitrary code by uploading a PHP file via the upload parameter to images.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2263

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2265

    Last Modified: 16 Apr 2026

    UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2271

    Last Modified: 16 Apr 2026

    Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2272

    Last Modified: 16 Apr 2026

    Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2273

    Last Modified: 16 Apr 2026

    efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2274

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2277

    Last Modified: 16 Apr 2026

    Buffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server response.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2279

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2288

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2289

    Last Modified: 16 Apr 2026

    Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2290

    Last Modified: 16 Apr 2026

    Microsoft Windows XP Explorer allows attackers to execute arbitrary code via a HTML and script in a self-executing folder that references an executable file within the folder, which is automatically executed when a user accesses the folder.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2291

    Last Modified: 16 Apr 2026

    Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script that uses Shell Helper objects and a shortcut (link) to execute the target script.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2292

    Last Modified: 16 Apr 2026

    Buffer overflow in Alt-N MDaemon 7.0.1 allows remote attackers to cause a denial of service (application crash) via a long STATUS command to the IMAP server.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2296

    Last Modified: 16 Apr 2026

    The preview_review function in the Reviews module in PHP-Nuke 6.0 to 7.3, when running on Windows systems, allows remote attackers to obtain sensitive information via an invalid date parameter, which generates an error message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2297

    Last Modified: 16 Apr 2026

    The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large, out-of-range score parameter.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2298

    Last Modified: 16 Apr 2026

    Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentication credential, which allows remote attackers to read and write mail store data if the administrator does not change the credential by using the NMAP Credential Generator.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2299

    Last Modified: 16 Apr 2026

    Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2301

    Last Modified: 16 Apr 2026

    Eudora before 6.1.1 allows remote attackers to cause a denial of service (crash) via an e-mail with a long "To:" field, possibly due to a buffer overflow.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2463

    Last Modified: 16 Apr 2026

    Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2306

    Last Modified: 16 Apr 2026

    Sun Solaris 7 through 9, when Basic Security Module (BSM) is enabled and the SUNWscpu package has been removed as a result of security hardening, disables mail alerts from the audit_warn script, which might allow attackers to escape detection.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2307

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2308

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the dir parameter in dohtaccess.html.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2309

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multiple ../ (dot dot slash) in the DIR command.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2310

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.

    Published: 31 Dec 2004
    3.6
    Low

    CVE-2004-2311

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2315

    Last Modified: 16 Apr 2026

    Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIONS request.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2316

    Last Modified: 16 Apr 2026

    Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via a GET request containing an MS-DOS device name such as COM1.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2317

    Last Modified: 16 Apr 2026

    Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2318

    Last Modified: 16 Apr 2026

    The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.

    Published: 31 Dec 2004
    3.6
    Low

    CVE-2004-2319

    Last Modified: 16 Apr 2026

    IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log file to onedcu or (2) read arbitrary files via a symlink attack on a file in /tmp to onshowaudit.

    Published: 31 Dec 2004