CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-2635

    Last Modified: 16 Apr 2026

    An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that use the control's RegQueryValue() method.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2640

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2641

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cause a denial of service (system controller hang) via IP Packets With Type of Service (TOS) Bits set.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2642

    Last Modified: 16 Apr 2026

    Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender.

    Published: 31 Dec 2004
    3.7
    Low

    CVE-2004-2643

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2644

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "ANY" type tags.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2645

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "CHOICE" types with "indefinite length structures."

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2639

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2651

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web script or HTML via the (1) urlmaskfilter parameter to index.html or the (2) page parameter to Wiki.html.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2653

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2681

    Last Modified: 16 Apr 2026

    PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session.

    Published: 31 Dec 2004
    5.8
    Medium

    CVE-2004-2649

    Last Modified: 16 Apr 2026

    Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as "&#32") in the middle of the URL.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2661

    Last Modified: 16 Apr 2026

    Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2662

    Last Modified: 16 Apr 2026

    Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) via certain data related to OpenSSL, which causes a thread to terminate but continue to hold resources.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2663

    Last Modified: 16 Apr 2026

    The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2666

    Last Modified: 16 Apr 2026

    Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote attackers to obtain sensitive information (private bug details) by visiting a bug's web page.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2667

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2668

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Interchange before 4.8.9 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2669

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Land Down Under (LDU) v701 allow remote attackers to execute arbitrary SQL commands or obtain the installation path via parameters including (1) s, w, and d in users.php, (2) id in comments.php, (3) rusername in auth.php, or (4) h in plug.php.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2670

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewcat operation or (2) the query parameter in a search operation in the publisher module.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2671

    Last Modified: 16 Apr 2026

    mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certain requests with invalid parameter values, which reveal the path in various error messages, as demonstrated by the (1) mod and (2) cid parameters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2672

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in ArGoSoft FTP server before 1.4.2.2 allows attackers to upload .lnk files via unknown vectors.

    Published: 31 Dec 2004
    4.9
    Medium

    CVE-2004-2665

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.00, B.11.04, and B.11.11 before 20040628 allows local users to cause a denial of service via unspecified vectors.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2675

    Last Modified: 16 Apr 2026

    ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password parameter, which causes the database to be corrupted.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2676

    Last Modified: 16 Apr 2026

    The Spy Sweeper Enterprise Client (SpySweeperTray.exe) in WebRoot Spy Sweeper before 2.0 does not drop privileges when using the help functionality, which allows local users to gain privileges.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-2678

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in HP Tru64 UNIX 5.1B PK2(BL22) and PK3(BL24), and 5.1A PK6(BL24), when using IPsec/IKE (Internet Key Exchange) with Certificates, allows remote attackers to gain privileges via unknown attack vectors.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2679

    Last Modified: 16 Apr 2026

    Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2685

    Last Modified: 16 Apr 2026

    Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2686

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2688

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2689

    Last Modified: 16 Apr 2026

    NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2693

    Last Modified: 16 Apr 2026

    HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privileges via files in /opt/gnome/src/GLib/.

    Published: 31 Dec 2004
    5.8
    Medium

    CVE-2004-2694

    Last Modified: 16 Apr 2026

    Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".

    Published: 31 Dec 2004
    5.5
    Medium

    CVE-2004-2696

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2636

    Last Modified: 16 Apr 2026

    TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2520

    Last Modified: 16 Apr 2026

    POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2519

    Last Modified: 16 Apr 2026

    Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specifiers in the LANGUAGE parameter to (1) index.tmpl and (2) web.tmpl, such as (a) slash "/", (b) backslash "\", (c) dot ".",, (d) dot dot "..", and (e) internal slash "lang//en".

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2517

    Last Modified: 16 Apr 2026

    myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2516

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2507

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to read arbitrary files via an absolute pathname in the next_file parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2510

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2500

    Last Modified: 16 Apr 2026

    Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2501

    Last Modified: 16 Apr 2026

    Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the connection.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2502

    Last Modified: 16 Apr 2026

    im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2503

    Last Modified: 16 Apr 2026

    INweb Mail Server 2.40 allows remote attackers to cause a denial of service (crash) via a large number of connect/disconnect actions to the (1) POP3 and (2) SMTP services.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2504

    Last Modified: 16 Apr 2026

    The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2499

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier allows remote attackers to cause a denial of service via unknown attack vectors when a web site is "improperly accessed."

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2508

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in main.cgi in Linksys WVC11B Wireless-B Internet Video Camera allows remote attackers to inject arbitrary web script or HTML via the next_file parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2458

    Last Modified: 16 Apr 2026

    Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2457

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in 3Com OfficeConnect ADSL 11g Router allows remote attackers to cause a denial of service (crash) via a large amount of UDP traffic.

    Published: 31 Dec 2004