CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2004-2521

    Last Modified: 16 Apr 2026

    Mail server in Gattaca Server 2003 1.1.10.0 allows remote attackers to perform a denial of service (application crash) via a large number of connections to TCP port (1) 25 (SMTP) or (2) 110 (POP).

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2512

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2509

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2506

    Last Modified: 16 Apr 2026

    Unparsed web content delivery vulnerability in WIKINDX before 0.9.9g allows remote attackers to obtain sensitive information via a direct HTTP request to the config.inc file.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2496

    Last Modified: 16 Apr 2026

    The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2485

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in PHP Live! before 2.8.2, due to a "major security problem," allows remote attackers to include arbitrary files and directories via unspecified attack vectors.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2481

    Last Modified: 16 Apr 2026

    MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2477

    Last Modified: 16 Apr 2026

    DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-2476

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.

    Published: 31 Dec 2004
    1.2
    Low

    CVE-2004-2473

    Last Modified: 16 Apr 2026

    wmFrog weather monitor 0.1.6 and other versions before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2465

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2474

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2475

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the Internet Zone. Thus this might not be a vulnerability.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2483

    Last Modified: 16 Apr 2026

    Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cache or cause a denial of service (connection loss).

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2484

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2486

    Last Modified: 16 Apr 2026

    The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2487

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2495

    Last Modified: 16 Apr 2026

    The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2498

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to determine internal directory structures via unknown attack vectors.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2515

    Last Modified: 16 Apr 2026

    Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already available to the attackers, so this might not be a vulnerability.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2522

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject arbitrary web script or HTML via the (1) template or (2) language parameter.

    Published: 31 Dec 2004
    5.4
    Medium

    CVE-2004-2527

    Last Modified: 16 Apr 2026

    The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2539

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Network Appliance NetCache 5.2 and Data ONTAP 6.0 allows remote attackers to cause a denial of service (panic and reboot) and possibly other impacts via unknown attack vectors, possibly related to unspecified worms, as identified by bug ID

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2543

    Last Modified: 16 Apr 2026

    Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy, or (3) invalid MIME messages to the mail filter. NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2546

    Last Modified: 16 Apr 2026

    Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2554

    Last Modified: 16 Apr 2026

    Novell Client Firewall (NCF) 2.0, as based on the Agnitum Outpost Firewall, allows local users to execute arbitrary code with SYSTEM privileges by opening the NCF tray icon and using the Help functionality to launch programs with SYSTEM privileges.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2572

    Last Modified: 16 Apr 2026

    AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable.

    Published: 31 Dec 2004
    5.8
    Medium

    CVE-2004-2580

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via unspecified vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2596

    Last Modified: 16 Apr 2026

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2598

    Last Modified: 16 Apr 2026

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will vary depending on which mod is being used.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2604

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2628

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2629

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2638

    Last Modified: 16 Apr 2026

    The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.

    Published: 31 Dec 2004
    4.9
    Medium

    CVE-2004-2650

    Last Modified: 16 Apr 2026

    Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2652

    Last Modified: 16 Apr 2026

    The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.

    Published: 31 Dec 2004
    4
    Medium

    CVE-2004-2659

    Last Modified: 16 Apr 2026

    Opera offers an Open button to verify that a user wishes to execute a downloaded file, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking Open via a request for a different mouse or keyboard action very shortly before the Open dialog appears. NOTE: this is a different issue than CVE-2005-2407.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2683

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2684

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, including (1) cache.key and (2) cache.dat, related to .csp files under (a) Dev\studio\templates and (b) Devuser\studio\templates.

    Published: 31 Dec 2004
    7.1
    High

    CVE-2004-2691

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web management interface. NOTE: the provenance of this information is unknown; details are obtained from third party reports.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2699

    Last Modified: 16 Apr 2026

    deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2707

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Gyach Enhanced (Gyach-E) before 1.0.5 have unknown impact and attack vectors related to "several security flaws," probably related to buffer overflows in HTTP server responses.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2709

    Last Modified: 16 Apr 2026

    Buffer overflow in the strip_html_tags method for Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors involving HTML tags.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2730

    Last Modified: 16 Apr 2026

    Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2758

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the H.323 protocol implementation for Sun SunForum 3.2 and 3D 1.0 allow remote attackers to cause a denial of service (segmentation fault and process crash), as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-0090

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-0390

    Last Modified: 16 Apr 2026

    SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-0498

    Last Modified: 16 Apr 2026

    The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-0567

    Last Modified: 16 Apr 2026

    The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-0592

    Last Modified: 16 Apr 2026

    The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type, a similar flaw to CVE-2004-0626.

    Published: 31 Dec 2004