CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2004-0789

    Last Modified: 16 Apr 2026

    Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by triggering a communications loop via (a) DNS query packets with localhost as a spoofed source address, or (b) a response packet that triggers a response packet.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-0997

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1049

    Last Modified: 16 Apr 2026

    Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1061

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bugzilla before 2.18, including 2.16.x before 2.16.11, allows remote attackers to inject arbitrary HTML and web script via forced error messages, as demonstrated using the action parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1143

    Last Modified: 16 Apr 2026

    The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.

    Published: 31 Dec 2004
    6
    Medium

    CVE-2004-1389

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1, and 4.5, DataCenter 3.4, 3.4.1, and 4.5, Enterprise Server 5.1, and NetBackup Server 5.0 and 5.1, allows attackers to execute arbitrary commands via the bpjava-susvc process, possibly related to the call-back feature.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-1390

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upscript, (5) downscript, (6) retries, (7) timeout, (8) scriptdetach, (9) noscript, (10) nodetach, (11) remote_mac, or (12) local_mac flags.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1395

    Last Modified: 16 Apr 2026

    The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that causes recvfrom to generate a return code that causes the listening loop to exit, as demonstrated using zero byte packets or packets between 8193 and 12280 bytes, which result in conditions that are not "Operation would block."

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-1398

    Last Modified: 16 Apr 2026

    Format string vulnerability in prelink.c in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via format string specifiers in the extension argument.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1399

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1410

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing error message, a different vulnerability than CVE-2004-1229.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1415

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in (1) disp_album.php and possibly (2) disp_img.php in 2Bgal 2.4 and 2.5.1 allows remote attackers to execute arbitrary SQL commands via the id_album parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1417

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1421

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1423

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1427

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1433

    Last Modified: 16 Apr 2026

    Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, and ONS 15600 1.x(x), allows remote attackers to cause a denial of service (control card reset) via malformed (1) TCP and (2) UDP packets.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1440

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash) and possibly execute arbitrary code via a large bignum during authentication.

    Published: 31 Dec 2004
    9.3
    Critical

    CVE-2004-1441

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1442

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to inject arbitrary web script or HTML via a macro filename, which is not properly handled by error messages such as "DTWP001E."

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1449

    Last Modified: 16 Apr 2026

    Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1450

    Last Modified: 16 Apr 2026

    Unknown vulnerability in LiveConnect in Mozilla 1.7 beta allows remote attackers to read arbitrary files in known locations.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1460

    Last Modified: 16 Apr 2026

    Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1467

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) date or search text field in the calendar module, (2) Field parameter, Filter parameter, QField parameter, Start parameter or Search field in the address module, (3) Subject field in the message module or (4) Subject field in the Ticket module.

    Published: 31 Dec 2004
    7.1
    High

    CVE-2004-1471

    Last Modified: 16 Apr 2026

    Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1473

    Last Modified: 16 Apr 2026

    Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1474

    Last Modified: 16 Apr 2026

    Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1475

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1) long VideoCD vcd:// MRLs or (2) long subtitle lines.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1485

    Last Modified: 16 Apr 2026

    Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1500

    Last Modified: 16 Apr 2026

    Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1502

    Last Modified: 16 Apr 2026

    The Telnet proxy in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (socket exhaustion) via a Telnet request to an IP address of the proxy's network interface, which causes a loop.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1503

    Last Modified: 16 Apr 2026

    Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1510

    Last Modified: 16 Apr 2026

    WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upcoming.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1519

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1553

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1560

    Last Modified: 16 Apr 2026

    Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1563

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1566

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1567

    Last Modified: 16 Apr 2026

    profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1571

    Last Modified: 16 Apr 2026

    AJ-Fork 167 allows remote attackers to gain sensitive information via a direct request to (1) auto-acronyms.php, (2) auto-archive.php, (3) ount-article-views.php, (4) kses.php, (5) custom-quick-tags.php, (6) disable-all-comments.php, (7) easy-date-format.php, (8) enable-disable-comments.php, (9) filter-by-author.php, (10) format-switcher.php, (11) long-to-short.php, (12) prospective-posting.php, or (13) sort-by-xfield.php, which displays the full path in an error message.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-1573

    Last Modified: 16 Apr 2026

    The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1576

    Last Modified: 16 Apr 2026

    Format string vulnerability in Judge Dredd: Dredd vs. Death 1.01 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a chat message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1585

    Last Modified: 16 Apr 2026

    Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1592

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1734

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1775

    Last Modified: 16 Apr 2026

    Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1787

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PostCalendar 4.0.0 allows remote attackers to execute arbitrary SQL commands via search queries.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1797

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1799

    Last Modified: 16 Apr 2026

    PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1807

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Published: 31 Dec 2004