CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2004-1867

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-1885

    Last Modified: 16 Apr 2026

    Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1894

    Last Modified: 16 Apr 2026

    TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-1903

    Last Modified: 16 Apr 2026

    Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1912

    Last Modified: 16 Apr 2026

    The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1951

    Last Modified: 16 Apr 2026

    xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite arbitrary files via the (1) audio.sun_audio_device or (2) dxr3.devicename options in an MRL link.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2012

    Last Modified: 16 Apr 2026

    The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2017

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inject arbitrary HTML or web script, as demonstrated via (1) the link parameter to ttt-out, (2) the X-Forwarded-For header in a GET request to ttt-in, (3) the Referer header in a GET request to ttt-in, or the (4) site name or (5) site URL fields in the main control panel.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2020

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 6.x through 7.3 allow remote attackers to inject arbitrary HTML or web script into the (1) optionbox parameter in the News module, (2) date parameter in the Statistics module, (3) year, month, and month_1 parameters in the Stories_Archive module, (4) mode, order, and thold parameters in the Surveys module, or (5) a SQL statement to index.php, as processed by mainfile.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2045

    Last Modified: 16 Apr 2026

    The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2098

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-2099

    Last Modified: 16 Apr 2026

    Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2103

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2107

    Last Modified: 16 Apr 2026

    Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart the service, (2) use the getlastmsg command to view log information, or (3) use the online command to force a policy update from the database server.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2143

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the com_remository option.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2151

    Last Modified: 16 Apr 2026

    Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2163

    Last Modified: 16 Apr 2026

    login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2172

    Last Modified: 16 Apr 2026

    EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2200

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2203

    Last Modified: 16 Apr 2026

    Ansel 1.2 through 2.0 uses insecure default permissions, which allows remote attackers to gain access to web readable directories.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2218

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2227

    Last Modified: 16 Apr 2026

    Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2237

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2248

    Last Modified: 16 Apr 2026

    Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions."

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2701

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2702

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to inject arbitrary web script or HTML via the login_name parameter. NOTE: this might be the same vector as CVE-2006-6451.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2704

    Last Modified: 16 Apr 2026

    Hastymail 1.0.1 and earlier (stable) and 1.1 and earlier (development) does not send the "attachment" parameter in the Content-Disposition field for attachments, which causes the attachment to be rendered inline by Internet Explorer when the victim clicks the download link, which facilitates cross-site scripting (XSS) and possibly other attacks.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2705

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain attributes of arbitrary accounts, including the password hash, via certain statsreq packets.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2711

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Gyach Enhanced (Gyach-E) before 1.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "avatar retrieval."

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2712

    Last Modified: 16 Apr 2026

    Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to "URL data."

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2723

    Last Modified: 16 Apr 2026

    NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-2717

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2718

    Last Modified: 16 Apr 2026

    PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2719

    Last Modified: 16 Apr 2026

    Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrary code via a mail message with a long From field, a different issue than CVE-2005-0339.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2720

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2721

    Last Modified: 16 Apr 2026

    The CheckGroup function in openSkat VTMF before 2.1 generates public key pairs in which the "p" variable might not be prime, which allows remote attackers to determine the private key and decrypt messages.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2722

    Last Modified: 16 Apr 2026

    Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2524

    Last Modified: 16 Apr 2026

    clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2525

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2526

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2528

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbitrary web script or HTML via the cam parameter.

    Published: 31 Dec 2004
    6.5
    Medium

    CVE-2004-2523

    Last Modified: 16 Apr 2026

    Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2532

    Last Modified: 16 Apr 2026

    Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2533

    Last Modified: 16 Apr 2026

    Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2534

    Last Modified: 16 Apr 2026

    Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2535

    Last Modified: 16 Apr 2026

    The person-to-person secure messaging feature in Sticker before 3.1.0 beta 2 allows remote attackers to post messages to unauthorized private groups by using the group's public encryption key.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2542

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Dynix (formerly known as epixtech) WebPAC allow remote attackers to execute arbitrary SQL commands via unknown attack vectors, resulting in an ability to execute stored procedures, bypass login authentication, and cause an unspecified denial of service to backend databases.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2544

    Last Modified: 16 Apr 2026

    Admin Console in Secure Computing Corporation Sidewinder G2 6.1.0.01 exports private keys when exporting firewall certificates, which might allow attackers to obtain sensitive information.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2548

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2549

    Last Modified: 16 Apr 2026

    Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (service crash) via a TCP request with a large string, followed by 8 newline characters, to (1) the Telnet service on TCP port 23 and (2) the HTTP service on TCP port 80, possibly due to a buffer overflow.

    Published: 31 Dec 2004