CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2004-1823

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1860

    Last Modified: 16 Apr 2026

    Buffer overflow in Check Point SmartDashboard in Check Point NG AI R54 and R55 allows remote authenticated users to cause a denial of service (server disconnect) and possibly execute arbitrary code via a large filter on a column when using SmartView Tracker.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1879

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows allows remote attackers to inject arbitrary web script or HTML via forum messages.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1891

    Last Modified: 16 Apr 2026

    The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged.

    Published: 31 Dec 2004
    5.5
    Medium

    CVE-2004-1901

    Last Modified: 16 Apr 2026

    Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1937

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. sequences in the file parameter with the page parameter set to globals, or (4) ../globals.php in the user_langue parameter, as demonstrated by modifying $nuked[prefix] in the Suggest module.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2021

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files via a .. (dot dot) in the filename argument.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2022

    Last Modified: 16 Apr 2026

    ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug is in Perl or the OS API that is used by Perl.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2046

    Last Modified: 16 Apr 2026

    Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of service via unknown attack vectors.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2048

    Last Modified: 16 Apr 2026

    radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2050

    Last Modified: 16 Apr 2026

    eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshell.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2054

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2065

    Last Modified: 16 Apr 2026

    DansGuardian 2.8 and earlier allows remote attackers to bypass the extension filtering rule via a hex encoded extension or . in the filename.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2108

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2119

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2123

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.asp, (2) searchKey parameter of searchresults.asp, and possibly (3) level parameter of ListCategories.asp.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2125

    Last Modified: 16 Apr 2026

    Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2126

    Last Modified: 16 Apr 2026

    The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2137

    Last Modified: 16 Apr 2026

    Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2144

    Last Modified: 16 Apr 2026

    Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2145

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2152

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2180

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum 1.61 allow remote attackers to inject arbitrary web script or HTML via the (1) country parameter to view_user.php, (2) show parameter to view_forum.php, (3) letter parameter to view_user.php, (4) highlight parameter to view_topic.php, (5) show parameter to index.php, (6) q parameter to search.php, (7) Referer header to admin.php, or the (8) user_email parameter to login.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2182

    Last Modified: 16 Apr 2026

    Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2191

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ttt-webmaster.php in Turbo Traffic Trader PHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) msg[0] or (2) siteurl parameters.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2201

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2202

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2204

    Last Modified: 16 Apr 2026

    Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administrative passwords by creating CFML scripts that use CreateObject or CFOBJECT.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2210

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to login.asp, or (6) the email parameter to subscribe/default.asp.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2239

    Last Modified: 16 Apr 2026

    Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2252

    Last Modified: 16 Apr 2026

    The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.

    Published: 31 Dec 2004
    5.3
    Medium

    CVE-2004-2257

    Last Modified: 16 Apr 2026

    phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2264

    Last Modified: 16 Apr 2026

    Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless there are plausible scenarios under which privilege boundaries could be crossed

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2268

    Last Modified: 16 Apr 2026

    PimenGest2 before 1.1.1 allows remote attackers to obtain the database password via debug information in rowLatex.inc.php.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2270

    Last Modified: 16 Apr 2026

    Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2275

    Last Modified: 16 Apr 2026

    i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2276

    Last Modified: 16 Apr 2026

    F-Secure Anti-Virus 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlier for Linux does not properly detect certain viruses in a PKZip archive, which allows viruses such as Sober.D and Sober.G to bypass initial detection.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2281

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2286

    Last Modified: 16 Apr 2026

    Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2287

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2294

    Last Modified: 16 Apr 2026

    Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter, which is checked for dangerous sequences before it is canonicalized, leading to a cross-site scripting (XSS) vulnerability.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2295

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2300

    Last Modified: 16 Apr 2026

    Buffer overflow in snmpd in ucd-snmp 4.2.6 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -p command line argument. NOTE: it is not clear whether there are any standard configurations in which snmpd is installed setuid or setgid. If not, then this issue should not be included in CVE.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-2302

    Last Modified: 16 Apr 2026

    Race condition in the sysfs_read_file and sysfs_write_file functions in Linux kernel before 2.6.10 allows local users to read kernel memory and cause a denial of service (crash) via large offsets in sysfs files.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2305

    Last Modified: 16 Apr 2026

    Computer Associates eTrust Antivirus EE 6.0 through 7.0 allows remote attackers to bypass virus scanning by including a password-protected file in a ZIP file, which causes eTrust to scan only the password protected file and skip the other files.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2312

    Last Modified: 16 Apr 2026

    Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2313

    Last Modified: 16 Apr 2026

    Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error messages for incorrect passwords versus correct passwords on non-mail-enabled accounts (such as root), which allows remote attackers to guess the root password via brute force attacks.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2314

    Last Modified: 16 Apr 2026

    The Telnet listener for Novell iChain Server before 2.2 Field Patch 3b 2.2.116 does not have a password by default, which allows remote attackers to gain access.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2322

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the (1) announce and (2) notes modules of phpWebSite before 0.9.3-2 allows remote attackers to execute arbitrary SQL queries, as demonstrated using the ANN_id parameter to the announce module.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2326

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was later reported to also affect firmware 4.0.34.

    Published: 31 Dec 2004