CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2004-2321

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2323

    Last Modified: 24 Apr 2026

    DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2325

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2327

    Last Modified: 16 Apr 2026

    Vizer Web Server 1.9.1 allows remote attackers to cause a denial of service (crash) via multiple malformed requests including (1) requests without GET, (2) GET requests without HTTP, (3) or long GET requests.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2328

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via an e-mail with a crafted RAR archive attached.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2330

    Last Modified: 16 Apr 2026

    ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a large number of form fields.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2332

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CPAN WWW::Form before 1.13 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2333

    Last Modified: 16 Apr 2026

    Bodington 2.1.0 RC1 and earlier does not secure the file upload area, which allows remote attackers to read uploaded files.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2335

    Last Modified: 16 Apr 2026

    The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studio, install the AuthenticationService setuid and writable by other users, which allows local users to gain privileges by modifying the program.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2336

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Novell GroupWise and GroupWise WebAccess 6.0 through 6.5, when running with Apache Web Server 1.3 for NetWare where Apache is loaded using GWAPACHE.CONF, allows remote attackers to read directories and files on the server.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2337

    Last Modified: 16 Apr 2026

    The /.inlook/.crypt file for inlook 0.7.3 and earlier is installed with world readable permissions, which allows local users to obtain user POP3 credentials.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2338

    Last Modified: 16 Apr 2026

    OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2460

    Last Modified: 16 Apr 2026

    Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2353

    Last Modified: 16 Apr 2026

    BugPort before 1.099 stores its configuration file (conf/config.conf) under the web document root with a file extension that is not normally parsed by web servers, which allows remote attackers to obtain sensitive information.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2357

    Last Modified: 16 Apr 2026

    The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, which allows remote attackers to read or modify the backend database.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2359

    Last Modified: 16 Apr 2026

    Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2367

    Last Modified: 16 Apr 2026

    The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of service (crash) via a long FTP command.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2371

    Last Modified: 16 Apr 2026

    Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly check return values from certain functions, which allows remote attackers to cause a denial of service (hang) via packets that contain text strings with incorrect size values.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2375

    Last Modified: 16 Apr 2026

    Buffer overflow in the POP3 server in 1st Class Mail Server 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an APOP USER command with a long second parameter (digest).

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2401

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text."

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2405

    Last Modified: 16 Apr 2026

    Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2410

    Last Modified: 16 Apr 2026

    Unknown vulnerability in sh_hash_compdata for Samhain 1.8.9 through 2.0.1 might allow attackers to cause a denial of service (null pointer dereference).

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2411

    Last Modified: 16 Apr 2026

    The CleanseMessage function in shop$db.asp for VP-ASP Shopping Cart 4.0 through 5.0 does not sufficiently cleanse inputs, which allows remote attackers to conduct cross-site scripting (XSS) attacks that do not use <script> tags, as demonstrated via javascript in IMG tags to (1) the cat parameter in shopdisplayproducts.asp or (2) the msg parameter in shoperror.asp, and possibly other vectors.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2418

    Last Modified: 16 Apr 2026

    Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2461

    Last Modified: 16 Apr 2026

    Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2433

    Last Modified: 16 Apr 2026

    Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2447

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in 1st Class Mail Server 4.01 allows remote attackers to inject arbitrary web script or HTML via the Mailbox parameter to (1) viewmail.tagz, (2) the index script under /user/, (3) members.tagz, (4) general.tagz, (5) advanced.tagz, or (6) list.tagz.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2450

    Last Modified: 16 Apr 2026

    The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2459

    Last Modified: 16 Apr 2026

    Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2466

    Last Modified: 16 Apr 2026

    chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2467

    Last Modified: 16 Apr 2026

    chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash).

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2468

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2469

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2470

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in MadBMS before 1.1.5 has unknown impact and attack vectors, related to logins.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2471

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the sloth TCL script in QuoteEngine before 1.2.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2472

    Last Modified: 16 Apr 2026

    Agnitum Outpost Pro Firewall 2.1 allows remote attackers to cause a denial of service (CPU consumption) via a flood of small, invalid packets, which can not be processed quickly enough by Outpost Pro.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2478

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2480

    Last Modified: 16 Apr 2026

    Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2482

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2488

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2489

    Last Modified: 16 Apr 2026

    Format string vulnerability in IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to execute arbitrary code via a modified INFORMIXDIR environment variable that points to a file with format string specifiers in the filename.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2490

    Last Modified: 16 Apr 2026

    Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.xC1 and 9.40.xC2 allows local users to execute arbitrary code via a long GL_PATH environment variable.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-2491

    Last Modified: 16 Apr 2026

    A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2492

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2493

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2494

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2497

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2505

    Last Modified: 16 Apr 2026

    Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2511

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid parameter in annoucement.php; (7) the cid parameter in news.php; (8) the cid parameter in contents.php; (9) the q parameter in search.php; and (10) the country parameter in register.php.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2513

    Last Modified: 16 Apr 2026

    Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command.

    Published: 31 Dec 2004