CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-0561

    Last Modified: 16 Apr 2026

    Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-0780

    Last Modified: 16 Apr 2026

    Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-0913

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ecartis 0.x before 0.129a+1.0.0-snap20020514-1.3 and 1.x before 1.0.0+cvs.20030911-8 allows attackers in the same domain to gain administrator privileges and modify configuration.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-0931

    Last Modified: 16 Apr 2026

    MySQL MaxDB before 7.5.00.18 allows remote attackers to cause a denial of service (crash) via an HTTP request to webdbm with high ASCII values in the Server field, which triggers an assert error in the IsAscii7 function.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-0943

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-0951

    Last Modified: 16 Apr 2026

    The make_recovery command for the TFTP server in HP Ignite-UX before C.6.2.241 makes a copy of the password file in the TFTP directory tree, which allows remote attackers to obtain sensitive information.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-0952

    Last Modified: 16 Apr 2026

    HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-0948

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. It was a duplicate assignment before public disclosure. Notes: none

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-0984

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-0999

    Last Modified: 16 Apr 2026

    zgv 5.5.3 allows remote attackers to cause a denial of service (application crash via segmentation fault) via crafted multiple-image (animated) GIF images.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1146

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1179

    Last Modified: 16 Apr 2026

    The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files via a symlink attack on temporary directories.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1182

    Last Modified: 16 Apr 2026

    hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1186

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).

    Published: 31 Dec 2004
    Unknown

    CVE-2004-1238

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004. Notes: none

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2266

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Ansel 2.1 and earlier allows remote attackers to modify SQL statements via the image parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-0369

    Last Modified: 16 Apr 2026

    Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-0555

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1150

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a long (1) device name or (2) sound track number, as demonstrated with a .m3u or .pls playlist file.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1306

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-1328

    Last Modified: 16 Apr 2026

    Unknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1388

    Last Modified: 16 Apr 2026

    Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1396

    Last Modified: 16 Apr 2026

    Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU consumption) via (1) an mp4 or m4a playlist file that contains invalid tag data or (2) an invalid .nsv or .nsa file.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1405

    Last Modified: 16 Apr 2026

    MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1432

    Last Modified: 16 Apr 2026

    Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed (1) IP or (2) ICMP packets.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1451

    Last Modified: 16 Apr 2026

    Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote attackers to trick users into clicking on unknown or untrusted sites and facilitate phishing attacks.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1459

    Last Modified: 16 Apr 2026

    Cisco Secure Access Control Server (ACS) 3.2, when configured as a Light Extensible Authentication Protocol (LEAP) RADIUS proxy, allows remote attackers to cause a denial of service (device crash) via certain LEAP authentication requests.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1481

    Last Modified: 16 Apr 2026

    Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-1483

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1491

    Last Modified: 16 Apr 2026

    Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-1557

    Last Modified: 16 Apr 2026

    MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a direct HTTP request to (1) /admin or (2) ServerProperties.html.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1509

    Last Modified: 16 Apr 2026

    validate.php in WebCalendar allows remote attackers to gain sensitive information via an invalid encoded_login parameter, which reveals the full path in an error message.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1518

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in follow.php in Phorum 5.0.12 and earlier allows remote authenticated users to execute arbitrary SQL command via the forum_id parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1527

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1545

    Last Modified: 16 Apr 2026

    UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1551

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1556

    Last Modified: 16 Apr 2026

    MyWebServer 1.0.3 allows remote attackers to cause a denial of service (application crash) via a large number of connections within a short time.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-1569

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that contains long File1 (filename) fields.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1572

    Last Modified: 16 Apr 2026

    AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1574

    Last Modified: 16 Apr 2026

    Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1582

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-1583

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1587

    Last Modified: 16 Apr 2026

    Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1666

    Last Modified: 16 Apr 2026

    Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1777

    Last Modified: 16 Apr 2026

    A "range check error" in Skype for Windows before 0.98.0.28 allows local and remote attackers to cause a denial of service (application crash) via long command line arguments or a long callto:// URL, a different vulnerability than CVE-2004-1114.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1796

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1798

    Last Modified: 16 Apr 2026

    RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than CVE-2003-0726.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1806

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1831

    Last Modified: 16 Apr 2026

    Buffer overflow in Chrome 1.2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large length value, which leads to a null dereference or out-of-bounds read.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1848

    Last Modified: 16 Apr 2026

    Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file.

    Published: 31 Dec 2004