CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2004-1463

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact.

    Published: 31 Dec 2004
    3.7
    Low

    CVE-2004-1465

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors, including the command line.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1466

    Last Modified: 16 Apr 2026

    The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the web root.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1461

    Last Modified: 16 Apr 2026

    Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the same IP address.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1462

    Last Modified: 16 Apr 2026

    Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (1) revert and (2) delete.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1472

    Last Modified: 16 Apr 2026

    Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-1469

    Last Modified: 16 Apr 2026

    Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6, allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1470

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1476

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1477

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Management Console in JRun 4.0 allows remote attackers to execute arbitrary web script or HTML and possibly hijack a user's session.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1478

    Last Modified: 16 Apr 2026

    JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1480

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the management station in HP StorageWorks Command View XP 1.8B and earlier allows remote attackers to bypass access restrictions.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-1479

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0928. Reason: This candidate is a duplicate of CVE-2004-0928. Notes: All CVE users should reference CVE-2004-0928 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1489

    Last Modified: 16 Apr 2026

    Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1490

    Last Modified: 16 Apr 2026

    Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1493

    Last Modified: 16 Apr 2026

    Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1494

    Last Modified: 16 Apr 2026

    Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption or application exit) and possibly execute arbitrary code via a long string.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1495

    Last Modified: 16 Apr 2026

    The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1496

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1497

    Last Modified: 16 Apr 2026

    Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1498

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1499

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1492

    Last Modified: 16 Apr 2026

    Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1504

    Last Modified: 16 Apr 2026

    The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1505

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1506

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar allow remote attackers to inject arbitrary web script via (1) view_entry.php, (2) view_d.php, (3) usersel.php, (4) datesel.php, (5) trailer.php, or (6) styles.php, as demonstrated using img srg tags.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1507

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in login.php in WebCalendar allows remote attackers to inject CRLF sequences via the return_path parameter and perform HTTP Response Splitting attacks to modify expected HTML content from the server.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1511

    Last Modified: 16 Apr 2026

    Hotfoon 4.0 does not notify users before opening links in web browsers, which could allow remote attackers to execute arbitrary code via a certain link sent in a chat window.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1512

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1513

    Last Modified: 16 Apr 2026

    04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1514

    Last Modified: 16 Apr 2026

    04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1515

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1516

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in index.php in phpWebSite 0.9.3-4 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the block_username parameter in the user module.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1517

    Last Modified: 16 Apr 2026

    Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1520

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1521

    Last Modified: 16 Apr 2026

    Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1522

    Last Modified: 16 Apr 2026

    Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1523

    Last Modified: 16 Apr 2026

    Format string vulnerability in the game console in Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1524

    Last Modified: 16 Apr 2026

    Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (game interruption) via a malformed UDP packet sent to a game port, such as port 29200.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1525

    Last Modified: 16 Apr 2026

    Hired Team: Trial 2.0 and earlier and 2.200 allows remote attackers to cause a denial of service (application crash) via the status command.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1526

    Last Modified: 16 Apr 2026

    Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, including the administrator.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1529

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1530

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1531

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1532

    Last Modified: 16 Apr 2026

    AppServ 2.5.x and earlier installs a default username and password, which allows remote attackers to gain access.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1533

    Last Modified: 16 Apr 2026

    Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1534

    Last Modified: 16 Apr 2026

    ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain JavaScript.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1544

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1528

    Last Modified: 16 Apr 2026

    The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1537

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.

    Published: 31 Dec 2004