CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-1404

    Last Modified: 16 Apr 2026

    Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1407

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in singapore Image Gallery Web Application 0.9.10 allow remote attackers to (1) read arbitrary files via the showThumb method for thumb.php, or (2) delete arbitrary files via admin.class.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1408

    Last Modified: 16 Apr 2026

    The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which allows remote attackers to upload and execute arbitrary files.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1409

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1411

    Last Modified: 16 Apr 2026

    Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1412

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1413

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1406

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1418

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail address, which is not quoted when a parsing error is generated.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-1419

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1420

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1422

    Last Modified: 16 Apr 2026

    WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1426

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1428

    Last Modified: 16 Apr 2026

    ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1429

    Last Modified: 16 Apr 2026

    ArGoSoft FTP 1.4.2.4 and earlier does not limit the number of times that a bad password can be entered, which makes it easier for remote attackers to guess passwords via a brute force attack.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1430

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the show_stats module in Arcade.php in IbProArcade allows remote attackers to execute arbitrary SQL code via the gameid parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1431

    Last Modified: 16 Apr 2026

    FormMail.php 5.0, and possibly other versions, allows remote attackers to read arbitrary files via a full pathname in the ar_file (auto-reply) parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1425

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1434

    Last Modified: 16 Apr 2026

    Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.1(0) to 4.1(2), 4.5(x), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via malformed SNMP packets.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1435

    Last Modified: 16 Apr 2026

    Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via a large number of TCP connections with an invalid response instead of the final ACK (TCP-ACK).

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1436

    Last Modified: 16 Apr 2026

    The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a password larger than 10 characters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1437

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute arbitrary code.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1438

    Last Modified: 16 Apr 2026

    The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1439

    Last Modified: 16 Apr 2026

    Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1443

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the inline MIME viewer in Horde-IMP (Internet Messaging Program) 3.2.4 and earlier, when used with Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via an e-mail message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1444

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.

    Published: 31 Dec 2004
    3.7
    Low

    CVE-2004-1445

    Last Modified: 16 Apr 2026

    A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1446

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1447

    Last Modified: 16 Apr 2026

    Jetbox One 2.0.8 and possibly other versions stores passwords in the database in plaintext, which could allow attackers to gain sensitive information.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1448

    Last Modified: 16 Apr 2026

    Jetbox One 2.0.8 and possibly other versions allow remote attackers with Author privileges in the IMAGES module to upload PHP files and execute arbitrary code.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-1452

    Last Modified: 16 Apr 2026

    Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1454

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-1402

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string parameter for index.php, (2) comments.php, or (3) the administrator login page.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1401

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1400

    Last Modified: 16 Apr 2026

    The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unauthorized access via a direct request to main.asp.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1394

    Last Modified: 16 Apr 2026

    The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1393

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the tcsetattr function for Sun Solaris for SPARC 2.6, 7, and 8 allows local users to cause a denial of service (system hang).

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1391

    Last Modified: 16 Apr 2026

    Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1387

    Last Modified: 16 Apr 2026

    The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1386

    Last Modified: 16 Apr 2026

    TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1385

    Last Modified: 16 Apr 2026

    phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1384

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1383

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1482

    Last Modified: 16 Apr 2026

    The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1343

    Last Modified: 16 Apr 2026

    CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-1330

    Last Modified: 16 Apr 2026

    Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1327

    Last Modified: 16 Apr 2026

    Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a file name with a long extension.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1296

    Last Modified: 16 Apr 2026

    The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2190

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Unzoo 4.4-2 has unknown impact and attack vectors.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1508

    Last Modified: 16 Apr 2026

    init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.

    Published: 31 Dec 2004