CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2004-2564

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parameter in showperf.asp.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2566

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2567

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ReciPants 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2568

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ReciPants 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user id, (2) recipe id, (3) category id, and (4) other ID number fields.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2570

    Last Modified: 16 Apr 2026

    Opera before 7.54 allows remote attackers to modify properties and methods of the location object and execute Javascript to read arbitrary files from the client's local filesystem or display a false URL to the user.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2565

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a "..\" (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2574

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2575

    Last Modified: 16 Apr 2026

    phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (2) hook_home.inc.php, (3) class.holidaycalc.inc.php, and (4) setup.inc.php.sample, which reveals the path in an error message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2576

    Last Modified: 16 Apr 2026

    class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-directory files, which allows remote attackers to obtain sensitive information from these files.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2577

    Last Modified: 16 Apr 2026

    The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote attackers to obtain sensitive information via WebDAV from users' home directories that lack .htaccess files, and possibly has other unknown impacts.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2578

    Last Modified: 16 Apr 2026

    phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2582

    Last Modified: 16 Apr 2026

    Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote attackers to obtain sensitive information.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2583

    Last Modified: 16 Apr 2026

    SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous open connections to TCP port 25.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2584

    Last Modified: 16 Apr 2026

    frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2585

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to inject arbitrary web script or HTML via Javascript to the "check spelling" feature in the compose area.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2586

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to read arbitrary files via the filename parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2587

    Last Modified: 16 Apr 2026

    login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a long txtusername parameter, possibly due to a buffer overflow.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2581

    Last Modified: 16 Apr 2026

    Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string."

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2590

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in meindlSOFT Cute PHP Library (aka cphplib) 0.46 has unknown impact and attack vectors, related to regular expressions.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2591

    Last Modified: 16 Apr 2026

    The data-overwrite capability of ButtUglySoftware CleanCache 2.19 does not properly overwrite data in files, which allows attackers to recover the data.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2592

    Last Modified: 16 Apr 2026

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not handled when processing Configstrings and Baselines.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2593

    Last Modified: 16 Apr 2026

    Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a packet with a long cmd_args buffer.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2594

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "\/" in a pathname argument, as demonstrated by "download \/server.cfg".

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2595

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a download command with a full pathname for a directory in the argument, which causes the server to crash when it cannot read data.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2589

    Last Modified: 16 Apr 2026

    Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length header, which causes Gaim to abort when attempting to allocate memory.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2601

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2602

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2599

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2607

    Last Modified: 16 Apr 2026

    A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loop from filling a buffer.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2609

    Last Modified: 16 Apr 2026

    The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2605

    Last Modified: 16 Apr 2026

    aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2613

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and attack vectors, related to "write access to specific proc entries from a vserver context", a different vulnerability than CVE-2004-2408.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2614

    Last Modified: 16 Apr 2026

    Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2615

    Last Modified: 16 Apr 2026

    The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2616

    Last Modified: 16 Apr 2026

    The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information by uploading a file, which reveals the path in a success message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2617

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2618

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2612

    Last Modified: 16 Apr 2026

    BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2621

    Last Modified: 16 Apr 2026

    Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway certificate until after a dialog box has been displayed to the user, which creates a race condition that allows remote attackers to perform a man-in-the-middle (MITM) attack.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2622

    Last Modified: 16 Apr 2026

    AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2623

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors and impact, possibly related to the "user-controlled filter."

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2624

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary web script or HTML via the "phrase" parameter.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-2625

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTML via Javascript in an attribute of an IMG tag.

    Published: 31 Dec 2004
    3.7
    Low

    CVE-2004-2626

    Last Modified: 16 Apr 2026

    GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2627

    Last Modified: 16 Apr 2026

    Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2620

    Last Modified: 16 Apr 2026

    The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers, which leads to a buffer underflow.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2631

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2632

    Last Modified: 16 Apr 2026

    phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-2633

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sesamie 1.0 allows remote anonymous attackers to gain access to repositories of other users via unknown vectors.

    Published: 31 Dec 2004
    6.2
    Medium

    CVE-2004-2634

    Last Modified: 16 Apr 2026

    The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary files via a symlink attack on temporary files via unknown attack vectors.

    Published: 31 Dec 2004