CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2004-1808

    Last Modified: 16 Apr 2026

    Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1809

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1810

    Last Modified: 16 Apr 2026

    The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array object with a large size value, then writing into that array.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1811

    Last Modified: 16 Apr 2026

    The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-1812

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 allow remote attackers to execute arbitrary code.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1813

    Last Modified: 16 Apr 2026

    VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trailing slash (/).

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1814

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via .. (dot dot) sequences in an HTTP request, as demonstrated using home.asp.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1828

    Last Modified: 16 Apr 2026

    Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote attackers to uninstall Vcard and delete database tables via a direct request to uninstall.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1858

    Last Modified: 16 Apr 2026

    HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the "$" character.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1824

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web script or HTML via the what parameter to memberlist.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1835

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1836

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1837

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1832

    Last Modified: 16 Apr 2026

    Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.

    Published: 31 Dec 2004
    8.8
    High

    CVE-2004-1842

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1844

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1845

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1841

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1863

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an arbitrary parameter in phpinfo.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1873

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via the catcode parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1880

    Last Modified: 16 Apr 2026

    Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1881

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execute arbitrary SQL commands via the strItems parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1882

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbitrary web script or HTML via the strImageTag parameter.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-1883

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a reply to a STAT command while a file is being transferred.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1887

    Last Modified: 16 Apr 2026

    Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1892

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to execute arbitrary code via a long string.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1893

    Last Modified: 16 Apr 2026

    Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1888

    Last Modified: 16 Apr 2026

    display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.

    Published: 31 Dec 2004
    7.6
    High

    CVE-2004-1896

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in in_mod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1897

    Last Modified: 16 Apr 2026

    Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes Monit to decrement a null pointer and perform an out-of-bounds read.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-1898

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1899

    Last Modified: 16 Apr 2026

    The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1900

    Last Modified: 16 Apr 2026

    Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1902

    Last Modified: 16 Apr 2026

    The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1895

    Last Modified: 16 Apr 2026

    YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1905

    Last Modified: 16 Apr 2026

    ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSitesFile function.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1906

    Last Modified: 16 Apr 2026

    Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM object, which may trigger a buffer overflow.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1907

    Last Modified: 16 Apr 2026

    The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12%13".

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1908

    Last Modified: 16 Apr 2026

    McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation function with certain parameters.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1909

    Last Modified: 16 Apr 2026

    Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1910

    Last Modified: 16 Apr 2026

    rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1911

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) l parameter (aka language variable) to index.php or (2) id parameter to view.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1904

    Last Modified: 16 Apr 2026

    Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property followed by a long string.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1914

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1913

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1940

    Last Modified: 16 Apr 2026

    sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-bounds read.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1949

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PostNuke 7.2.6 and earlier allows remote attackers to execute arbitrary SQL via (1) the sif parameter to index.php in the Comments module or (2) timezoneoffset parameter to changeinfo.php in the Your_Account module.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1955

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in modules.php in phProfession 2.5 allows remote attackers to execute arbitrary SQL code via the offset parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1960

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in blocker_query.php in Protector System 1.15b1 allows remote attackers to inject arbitrary web script or HTML via the (1) target or (2) portNum parameters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1962

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection filters by using "/**/" sequences in the targeted fields.

    Published: 31 Dec 2004