CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2004-2514

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web script or HTML via the (1) SUBJECT or (2) MESSAGE field.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2518

    Last Modified: 16 Apr 2026

    Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00") to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2537

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."

    Published: 31 Dec 2004
    6.5
    Medium

    CVE-2004-2538

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows remote authenticated users to execute arbitrary code via the (1) header or (2) footer.

    Published: 31 Dec 2004
    6.9
    Medium

    CVE-2004-2541

    Last Modified: 16 Apr 2026

    Buffer overflow in Cscope 15.5, and possibly multiple overflows, allows remote attackers to execute arbitrary code via a C file with a long #include line that is later browsed by the target.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2545

    Last Modified: 16 Apr 2026

    Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an "extremely busy network." NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2561

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Internet Software Sciences Web+Center 4.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the ISS_TECH_CENTER_LOGIN cookie in search.asp and (2) one or more cookies in DoCustomerOptions.asp.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2571

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in EnderUNIX isoqlog 2.1.1 allow remote attackers to execute arbitrary code via the (1) parseQmailFromBytesLine, (2) parseQmailToRemoteLine, (3) parseQmailToLocalLine, (4) parseSendmailFromBytesLine, (5) parseSendmailToLine, (6) parseEximFromBytesLine, and (7) parseEximToLine functions in Parser.c; allow local users to execute arbitrary code via the (8) lowercase and (9) check_syslog_date functions in Parser.c, and (10) unspecified functions in Dir.c; and allow unspecified attackers to execute arbitrary code via the (11) loadconfig and (12) removespaces functions in loadconfig.c, the (13) loadLang function in LangCfg.c, and (14) unspecified functions in Html.c.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2579

    Last Modified: 16 Apr 2026

    ACLCHECK module in Novell iChain 2.3 allows attackers to bypass access control rules of an unspecified component via an unspecified attack vector involving a string that contains escape sequences represented with "overlong UTF-8 encoding."

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2588

    Last Modified: 16 Apr 2026

    Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2562

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2603

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2608

    Last Modified: 16 Apr 2026

    SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2610

    Last Modified: 16 Apr 2026

    mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount option in the configuration file. NOTE: It is not clear whether this is a vulnerability because there is not necessarily any common usage in which privilege boundaries are crossed. Typical usage would restrict write access to the configuration file.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2611

    Last Modified: 16 Apr 2026

    The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized activities.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2606

    Last Modified: 16 Apr 2026

    The Web interface in Linksys WRT54G 2.02.7 and BEFSR41 version 3, with the firewall disabled, allows remote attackers to attempt to login to an administration web page, even when the configuration specifies that remote administration is disabled.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2258

    Last Modified: 16 Apr 2026

    Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2247

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2246

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2245

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Goollery 0.03 allows remote attackers to inject arbitrary HTML or web script via the (1) page parameter to viewalbum.php or (2) btopage parameter to viewpic.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2244

    Last Modified: 16 Apr 2026

    The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2243

    Last Modified: 16 Apr 2026

    Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7, but this may be erroneous.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2241

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2240

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2726

    Last Modified: 16 Apr 2026

    HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the Authorization header, which allows remote attackers to cause a denial of service (null dereference and application crash). NOTE: This is a different vulnerability than CVE-2005-1348.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2727

    Last Modified: 16 Apr 2026

    Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a denial of service (application crash) via a long HTTP GET request.

    Published: 31 Dec 2004
    3.5
    Low

    CVE-2004-2728

    Last Modified: 16 Apr 2026

    Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a denial of service (application crash) via a long argument to the XCWD command.

    Published: 31 Dec 2004
    4.4
    Medium

    CVE-2004-2729

    Last Modified: 16 Apr 2026

    Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2737

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2738

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in check_user_id.php in ZeroBoard 4.1pl4 and earlier allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2739

    Last Modified: 16 Apr 2026

    The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vectors.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2743

    Last Modified: 16 Apr 2026

    upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unspecified parameters related to names of uploaded files.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2744

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Tincan Limited PHPlist before 2.8.12 has unknown impact and attack vectors, related to a "security update release."

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2745

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Anteco Visual Technologies OwnServer 1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2746

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2748

    Last Modified: 16 Apr 2026

    viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2742

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the report viewer in Crystal Enterprise 8.5, 9, and 10 allows remote attackers to inject arbitrary web script or HTML via script in the URL to a report (RPT) file.

    Published: 31 Dec 2004
    5.6
    Medium

    CVE-2004-2753

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in SharedX in HP-UX B.11.00, B.11.11, and B.11.22 allows local users to access unspecified files or cause a denial of service via unknown vectors related to handling of "files in a potentially insecure manner."

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2754

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2755

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the query string in blocked URLs that are listed in (1) error or (2) block page messages.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2756

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject arbitrary web script or HTML via the (1) forum and (2) topic_id parameters.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2751

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the members_list module in PostNuke 0.726, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-9998

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate has been used as a placeholder by multiple organizations for multiple issues, but it is invalid. Notes: All CVE users should search CVE for the proper identifier. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2004
    Unknown

    CVE-2004-0410

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-0429

    Last Modified: 16 Apr 2026

    Unknown vulnerability related to "the handling of large requests" in RAdmin for Apple Mac OS X 10.3.3 and Mac OS X 10.2.8 may allow attackers to have unknown impact via unknown attack vectors.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-0462

    Last Modified: 16 Apr 2026

    The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-0467

    Last Modified: 16 Apr 2026

    Juniper JUNOS 5.x through JUNOS 7.x allows remote attackers to cause a denial of service (routing disabled) via a large number of MPLS packets, which are not filtered or verified before being sent to the Routing Engine, which reduces the speed at which other packets are processed.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-0499

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-0533

    Last Modified: 16 Apr 2026

    Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-0560

    Last Modified: 16 Apr 2026

    Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted content of a certain size that triggers the overflow.

    Published: 31 Dec 2004