CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2004-1464

    Last Modified: 16 Apr 2026

    Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2355

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the name field of a livehelp or chat session.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1953

    Last Modified: 16 Apr 2026

    phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which reveals the path in a PHP error message.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1552

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-1241

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004. Notes: none

    Published: 31 Dec 2004
    Unknown

    CVE-2004-1243

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004. Notes: none

    Published: 31 Dec 2004
    Unknown

    CVE-2004-1242

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004. Notes: none

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2759

    Last Modified: 16 Apr 2026

    Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2757

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the failed login page in Novell iChain before 2.2 build 2.2.113 and 2.3 First Customer Ship (FCS) allows remote attackers to inject arbitrary web script or HTML via url parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2752

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2750

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2749

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2736

    Last Modified: 16 Apr 2026

    Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2735

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in P4DB 2.01 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) SET_PREFERENCES parameter in SetPreferences.cgi; (2) BRANCH parameter in branchView.cgi; (3) FSPC and (4) COMPLETE parameters in changeByUsers.cgi; (5) FSPC, (6) LABEL, (7) EXLABEL, (8) STATUS, (9) MAXCH, (10) FIRSTCH, (11) CHOFFSETDISP, (12) SEARCHDESC, (13) SEARCH_INVERT, (14) USER, (15) GROUP, and (16) CLIENT parameters in changeList.cgi; (17) CH parameter in changeView.cgi; (18) USER parameter in clientList.cgi; (19) CLIENT parameter in clientView.cgi; (20) FSPC parameter in depotTreeBrowser.cgi; (21) FSPC parameter in depotStats.cgi; (22) FSPC, (23) REV, (24) ACT, (25) FSPC2, (26) REV2, (27) CH, and (28) CONTEXT parameters in fileDiffView.cgi; (29) FSPC and (30) REV parameters in fileDownLoad.cgi; (31) FSPC, (32) LISTLAB, and (33) SHOWBRANCH parameters in fileLogView.cgi; (34) FSPC and (35) LABEL parameters in fileSearch.cgi; (36) FSPC, (37) REV, and (38) FORCE parameters in fileViewer.cgi; (39) FSPC parameter in filesChangedSince.cgi; (40) GROUP parameter in groupView.cgi; (41) TYPE, (42) FSPC, and (43) REV parameters in htmlFileView.cgi; (44) CMD parameter in javaDataView.cgi; (45) JOBVIEW and (46) FLD parameters in jobList.cgi; (47) JOB parameter in jobView.cgi; (48) LABEL1 and (49) LABEL2 parameters in labelDiffView.cgi; (50) LABEL parameter in labelView.cgi; (51) FSPC parameter in searchPattern.cgi; (52) TYPE, (53) FSPC, and (54) REV parameters in specialFileView.cgi; (55) GROUPSONLY parameter in userList.cgi; or (56) USER parameter in userView.cgi.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2734

    Last Modified: 16 Apr 2026

    webadmin-apache.conf in Novell Web Manager of Novell NetWare 6.5 uses an uppercase Alias tag with an inconsistent lowercase directory tag for a volume, which allows remote attackers to bypass access control to the WEB-INF folder.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2725

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email parameter in (b) subscribe.php, and (3) the return and (4) title parameters in (c) forum_2.php.

    Published: 31 Dec 2004
    7.1
    High

    CVE-2004-2724

    Last Modified: 16 Apr 2026

    LionMax Software Chat Anywhere 2.72a allows remote attackers to cause a denial of service (server crash and client CPU consumption) via a username beginning with percent (%) followed by a null character.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2716

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2715

    Last Modified: 16 Apr 2026

    edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.

    Published: 31 Dec 2004
    6
    Medium

    CVE-2004-2714

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Window Maker 0.80.2 and earlier allows attackers to perform unknown actions via format string specifiers in a font specification in WMGLOBAL, probably a format string vulnerability.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2708

    Last Modified: 16 Apr 2026

    Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by reading the configuration file.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2703

    Last Modified: 16 Apr 2026

    Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".

    Published: 31 Dec 2004
    9
    Critical

    CVE-2004-2700

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.

    Published: 31 Dec 2004
    6.9
    Medium

    CVE-2004-2697

    Last Modified: 16 Apr 2026

    The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2695

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to CVE-2006-4267.

    Published: 31 Dec 2004
    9.3
    Critical

    CVE-2004-2692

    Last Modified: 16 Apr 2026

    The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd function.

    Published: 31 Dec 2004
    9.3
    Critical

    CVE-2004-2687

    Last Modified: 16 Apr 2026

    distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2677

    Last Modified: 16 Apr 2026

    Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2674

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to determine the existence of arbitrary files via ".." sequences in the SITE UNZIP argument.

    Published: 31 Dec 2004
    9
    Critical

    CVE-2004-2673

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in ArGoSoft FTP Server before 1.4.1.6 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a SITE ZIP command with a long first or second argument, or (2) a SITE COPY with a long argument.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2664

    Last Modified: 16 Apr 2026

    John Lim ADOdb Library for PHP before 4.23 allows remote attackers to obtain sensitive information via direct requests to certain scripts that result in an undefined value of ADODB_DIR, which reveals the installation path in an error message.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2658

    Last Modified: 16 Apr 2026

    resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login types.

    Published: 31 Dec 2004
    1.7
    Low

    CVE-2004-2657

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.

    Published: 31 Dec 2004
    1
    Low

    CVE-2004-2648

    Last Modified: 16 Apr 2026

    FreezeX 1.00.100.0666 allows local users with administrator privileges to cause a denial of service (FreezeX application) by overwriting the db.fzx file.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2630

    Last Modified: 16 Apr 2026

    The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2619

    Last Modified: 16 Apr 2026

    ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2600

    Last Modified: 16 Apr 2026

    The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2597

    Last Modified: 16 Apr 2026

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the client's IP address.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2573

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in the appdir parameter.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2569

    Last Modified: 16 Apr 2026

    ipmenu 0.0.3 before Debian GNU/Linux ipmenu_0.0.3-5 allows local users to overwrite arbitrary files via a symlink attack on the ipmenu.log temporary file.

    Published: 31 Dec 2004
    5.8
    Medium

    CVE-2004-2563

    Last Modified: 16 Apr 2026

    Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2558

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for Multi-platforms 2.1.3 to 2.15 allow remote attackers to hijack sessions of authenticated users via unknown attack vectors involving certain cookies, aka "Potential Credential Impersonation Attack."

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2556

    Last Modified: 16 Apr 2026

    NetGear WG602 (aka WG602v1) Wireless Access Point firmware 1.04.0 and 1.5.67 has a hardcoded account of username "super" and password "5777364", which allows remote attackers to modify the configuration.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2555

    Last Modified: 16 Apr 2026

    Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2551

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter in manageanalgrouppreference.asp, (5) the sys_asset_id parameter in quickinfoassetrequests.asp, (6) the sys_eusername parameter in quickinfoenduserrequests.asp, and the sys_request_id parameter in (7) requestauditlog.asp, (8) requestcommentsenduser.asp, (9) selectrequestapplytemplate.asp, and (10) selectrequestlink.asp, resulting in an ability to create a new HelpBox user account and read, modify, or delete data from the backend database.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2540

    Last Modified: 16 Apr 2026

    readObject in (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.0 through 1.4.2_05 allows remote attackers to cause a denial of service (JVM unresponsive) via crafted serialized data.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2536

    Last Modified: 16 Apr 2026

    The exit_thread function (process.c) in Linux kernel 2.6 through 2.6.5 does not invalidate the per-TSS io_bitmap pointers if a process obtains IO access permissions from the ioperm function but does not drop those permissions when it exits, which allows other processes to access the per-TSS pointers, access restricted memory locations, and possibly gain privileges.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2531

    Last Modified: 16 Apr 2026

    X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-2530

    Last Modified: 16 Apr 2026

    Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2529

    Last Modified: 16 Apr 2026

    Gadu-Gadu allows remote attackers to bypass the "image send" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities.

    Published: 31 Dec 2004