CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2004-2329

    Last Modified: 16 Apr 2026

    Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges before opening the file loading dialog box.

    Published: 31 Dec 2004
    5.5
    Medium

    CVE-2004-2331

    Last Modified: 16 Apr 2026

    ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2334

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable parameter in emumail.fcgi, (2) the folder parameter in emumail.fcgi, or Javascript in the (3) username or (4) password field in the login page.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2340

    Last Modified: 16 Apr 2026

    ** UNVERIFIABLE ** SQL injection vulnerability in PunkBuster Screenshot Database (PB-DB) Alpha 6 allows remote attackers to execute arbitrary SQL commands via the username and password fields of the login form. NOTE: the original vulnerability report contains several significant inconsistencies that make it unclear whether the report is accurate, including (1) PB-DB is really the "PunkBuster Screenshot Database" and not "PunkBuster" itself; (2) there is no apparent association between PunkBuster and "Punky Brewster"; (3) the claimed source code is not anywhere in Alpha 6.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2346

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm.

    Published: 31 Dec 2004
    6.8
    Medium

    CVE-2004-2354

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2360

    Last Modified: 16 Apr 2026

    Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which causes the server to enter an infinite loop while waiting to read the rest of the data that is not sent.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2361

    Last Modified: 16 Apr 2026

    Digital Reality game engine, as used in Haegemonia 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps 1.0, allows remote attackers to cause a denial of service (crash) via a chat message with a large message size, which triggers an out-of-bounds read.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2366

    Last Modified: 16 Apr 2026

    Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE command with a long argument.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2368

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in header.php in Opt-X 0.7.2 allows remote attackers to execute arbitrary PHP code via the systempath parameter.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2369

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-2383

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to bypass cross-frame scripting restrictions and capture keyboard events from other domains via an HTML document with Javascript that is outside a frameset that includes the target domain, then forcing the frameset to maintain focus. NOTE: the discloser claimed that the vendor does not categorize this as a vulnerability, but it can be used in a spoofing scenario; the discloser provides alternate scenarios. Spoofing scenarios are currently included in CVE.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2384

    Last Modified: 16 Apr 2026

    NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2395

    Last Modified: 16 Apr 2026

    Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2397

    Last Modified: 16 Apr 2026

    The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.

    Published: 31 Dec 2004
    3.6
    Low

    CVE-2004-2408

    Last Modified: 16 Apr 2026

    Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and host servers, which allows local users with the ability to set permissions in /proc to obtain system information or cause a denial of service on other virtual servers or the host server.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2413

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in VP-ASP Shopping Cart 4.0 through 5.0 allows remote attackers to execute arbitrary SQL commands via the (1) Processed0 and (2) Processed1 parameters in a POST request to shopproductselect.asp.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2420

    Last Modified: 16 Apr 2026

    Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7 allows remote attackers to cause a denial of service (daemon halt) via a port scan involving reset packets.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2421

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Hitachi Job Management Partner (JP1) JP1/File Transmission Server/FTP 6 and 7, when running on HP-UX in trusted mode, allows attackers to bypass authentication and gain administrator rights.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2425

    Last Modified: 16 Apr 2026

    Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary commands via accent (`) and possibly other shell metacharacters in the query string to virtualinput.cgi.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2427

    Last Modified: 16 Apr 2026

    Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cgi, modify system information via (5) setparam.cgi and (6) factorydefault.cgi, or (7) cause a denial of service (reboot) via restart.cgi.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2428

    Last Modified: 16 Apr 2026

    Abczone.it WWWguestbook 1.1 stores db/dbase.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the plaintext username and password.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2439

    Last Modified: 16 Apr 2026

    The remote upgrade capability in HP LaserJet 4200 and 4300 printers does not require a password, which allows remote attackers to upgrade firmware.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2444

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2449

    Last Modified: 16 Apr 2026

    Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2451

    Last Modified: 16 Apr 2026

    Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2452

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-2462

    Last Modified: 16 Apr 2026

    cplay 1.49 on Linux allows local users to overwrite arbitrary files via a symlink attack on the cplay_control temporary file.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2464

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2443

    Last Modified: 16 Apr 2026

    Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2442

    Last Modified: 16 Apr 2026

    Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on the target system.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2434

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-0465

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via "..//" sequences in the WCP_USER parameter.

    Published: 31 Dec 2004
    8.5
    High

    CVE-2004-0638

    Last Modified: 16 Apr 2026

    Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1.5, and 8i Release 1 8.1.7.4, allows remote authorized users to execute arbitrary code via a long second argument.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-0824

    Last Modified: 16 Apr 2026

    PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.

    Published: 31 Dec 2004
    4.6
    Medium

    CVE-2004-0919

    Last Modified: 16 Apr 2026

    The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1043

    Last Modified: 16 Apr 2026

    Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."

    Published: 31 Dec 2004
    Unknown

    CVE-2004-1239

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004. Notes: none

    Published: 31 Dec 2004
    Unknown

    CVE-2004-1240

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2004. Notes: none

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1332

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1397

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via an argument to wiki.pl.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1414

    Last Modified: 16 Apr 2026

    Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images.

    Published: 31 Dec 2004
    5.1
    Medium

    CVE-2004-1416

    Last Modified: 16 Apr 2026

    pnxr3260.dll in the RealOne 2.0 build 6.0.11.868 browser plugin, as used in Internet Explorer, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embed tag.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-1424

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1468

    Last Modified: 16 Apr 2026

    The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1484

    Last Modified: 16 Apr 2026

    Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-1486

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Serviceguard A.11.13 through A.11.16.00 and Cluster Object Manager A.01.03 and B.01.04 through B.03.00.01 on HP-UX, Serviceguard A.11.14.04 and A.11.15.04 and Cluster Object Manager B.02.01.02 and B.02.02.02 on HP Linux, allow remote attackers to gain privileges via unknown attack vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1501

    Last Modified: 16 Apr 2026

    The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1535

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1558

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.

    Published: 31 Dec 2004