CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-2456

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a userinfo action.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2455

    Last Modified: 16 Apr 2026

    Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2454

    Last Modified: 16 Apr 2026

    aMSN 0.90 for Microsoft Windows allows local users to obtain sensitive information such as hashed passwords from (1) hotlog.htm and (2) config.xml.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2453

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Tutti Nova 0.10 through 0.12 (Beta) and 0.9.4, when register_globals is enabled, has unknown impact and attack vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2448

    Last Modified: 16 Apr 2026

    S-Mart Shopping Cart or RediCart 3.9.5b stores smart.cfg under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the database name.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2446

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in 1st Class Mail Server 4.01 allows remote attackers to read arbitrary files via a ".." (dot dot) sequences in unknown vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2445

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a .. (dot dot) in the gadget parameter.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2440

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (username or password) of other users.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2438

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2437

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2436

    Last Modified: 16 Apr 2026

    Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2435

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitrary web script or HTML via unspecified (1) debugging or (2) utility scripts.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2432

    Last Modified: 16 Apr 2026

    WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2431

    Last Modified: 16 Apr 2026

    Unknown vulnerability in The Ignition Project ignitionServer 0.1.2 through 0.3.1, with the linking service enabled, allows remote attackers to bypass authentication.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2430

    Last Modified: 16 Apr 2026

    Trend OfficeScan Corporate Edition 5.58 and possibly earler does not drop privileges when opening a help window from a virus detection pop-up window, which allows local users to gain SYSTEM privileges.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2429

    Last Modified: 16 Apr 2026

    Multiple stack-based and heap-based buffer overflows in EnderUNIX spamGuard before 1.7-BETA allow remote attackers to execute arbitrary code via the (1) qmail_parseline and (2) sendmail_parseline functions in parser.c, (3) loadconfig and (4) removespaces functions in loadconfig.c, and possibly (5) unspecified functions in functions.c.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2424

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the server from releasing the network port when the session ends.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2423

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Web calendaring component of Ipswitch IMail Server before 8.13 allows remote attackers to cause a denial of service (crash) via "specific content."

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2422

    Last Modified: 16 Apr 2026

    Multiple features in Ipswitch IMail Server before 8.13 allow remote attackers to cause a denial of service (crash) via (1) a long sender field to the Queue Manager or (2) a long To field to the Web Messaging component.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2441

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue."

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2417

    Last Modified: 16 Apr 2026

    Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2416

    Last Modified: 16 Apr 2026

    Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2415

    Last Modified: 16 Apr 2026

    Davenport before 0.9.10 allows attackers to cause a denial of service (resource consumption) via (1) a very large XML file or (2) entity expansion attacks.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2414

    Last Modified: 16 Apr 2026

    Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with OpenSSH, includes sensitive password information in the (1) NIOUTPUT.TXT and (2) NI.LOG log files, which might allow local users to obtain the passwords.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-2404

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-2347. Reason: This candidate is a duplicate of CVE-2004-2347. Notes: All CVE users should reference CVE-2004-2347 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2409

    Last Modified: 16 Apr 2026

    Buffer overflow in the sh_hash_compdata function for Samhain 1.8.9 through 2.0.1, when running in update mode ("-t update"), might allow attackers to execute arbitrary code.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2407

    Last Modified: 16 Apr 2026

    Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Config functionality.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2406

    Last Modified: 16 Apr 2026

    Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2403

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2399

    Last Modified: 16 Apr 2026

    Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (CPU consumption) via delayed responses to DNS queries.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2398

    Last Modified: 16 Apr 2026

    Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2124

    Last Modified: 16 Apr 2026

    The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2142

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the remote tape support (remote.c) in the RMT client for Jorg Schilling sdd 1.28 and 1.31 has unknown impact and attack vectors.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2128

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2129

    Last Modified: 16 Apr 2026

    SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2236

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2138

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in AWSguest.php in AllWebScripts MySQLGuest allows remote attackers to inject arbitrary HTML and PHP code via the (1) Name, (2) Email, (3) Homepage or (4) Comments field.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2139

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2140

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-2141

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1827. Reason: This candidate is a duplicate of CVE-2004-1827. Notes: All CVE users should reference CVE-2004-1827 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2146

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2147

    Last Modified: 16 Apr 2026

    Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2148

    Last Modified: 16 Apr 2026

    Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2149

    Last Modified: 16 Apr 2026

    Buffer overflow in the prepared statements API in libmysqlclient for MySQL 4.1.3 beta and 4.1.4 allows remote attackers to cause a denial of service via a large number of placeholders.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2150

    Last Modified: 16 Apr 2026

    Nettica Corporation INTELLIPEER Email Server 1.01 displays different error messages for valid and invalid account names, which allows remote attackers to determine valid account names.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2153

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2157

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (1) email or (2) username field.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2158

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2159

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 have unknown impact and attack vectors via (1) xml_elem.c and (2) xml_select.c.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2160

    Last Modified: 16 Apr 2026

    Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.

    Published: 31 Dec 2004