CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2004-1559

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1575

    Last Modified: 16 Apr 2026

    The XML parser in Xerces-C++ 2.5.0 allows remote attackers to cause a denial of service (CPU consumption) via XML attributes in a crafted XML document.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1584

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1591

    Last Modified: 16 Apr 2026

    The web interface for Micronet Wireless Broadband Router SP916BM running firmware before 1.9 08/04/2004 resets the password to the default password when the router is shut off, which could allow remote attackers to gain access.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1725

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in xvbmp.c in XV allows remote attackers to execute arbitrary code via a crafted image file.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-1753

    Last Modified: 16 Apr 2026

    The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-1795

    Last Modified: 16 Apr 2026

    Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1869

    Last Modified: 16 Apr 2026

    Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (crash) by sending a packet that specifies the size for the next packet, then sending a larger packet than specified, which causes Etherlords to read unallocated memory.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1889

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-1958

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-1966

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter in board.php, (2) sortorder, perpage, or id parameters in member.php, (3) forums parameter in search.php, or (4) PID or FID parameters in post.php.

    Published: 31 Dec 2004
    7.8
    High

    CVE-2004-2013

    Last Modified: 16 Apr 2026

    Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2118

    Last Modified: 16 Apr 2026

    Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via a GET request with a long filename, possibly due to a buffer overflow.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2121

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2155

    Last Modified: 16 Apr 2026

    Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2173

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in advSearch_h.asp in EarlyImpact ProductCart allows remote attackers to execute arbitrary SQL commands via the priceUntil parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2181

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2192

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in tttadmin/settings.php in Turbo Traffic Trader PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the ttt_admin parameter.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2211

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to post.asp.

    Published: 31 Dec 2004
    2.6
    Low

    CVE-2004-2219

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javascript that uses an invalid URI, modifies the Location field, then uses history.back to navigate to the previous domain, aka NullyFake.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2228

    Last Modified: 16 Apr 2026

    Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2230

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2238

    Last Modified: 16 Apr 2026

    Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that, when compiled, became static format strings. Thus this is not a vulnerability

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2242

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2249

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the "access code" in SecureEditor before 0.1.2 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2250

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2251

    Last Modified: 16 Apr 2026

    The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2253

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2254

    Last Modified: 16 Apr 2026

    SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.

    Published: 31 Dec 2004
    6.4
    Medium

    CVE-2004-2255

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2256

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2267

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Ansel 2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via the album name.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2269

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in pads.c in Passive Asset Detection System (Pads) might allow local users to execute arbitrary code via a long report file name argument. NOTE: since Pads is not normally installed setuid, this may not be a vulnerability.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2278

    Last Modified: 16 Apr 2026

    Unknown cross-site scripting (XSS) vulnerability in the web GUI in vHost before 3.10r1 has unknown impact and attack vectors.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2280

    Last Modified: 16 Apr 2026

    Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2282

    Last Modified: 16 Apr 2026

    DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request.

    Published: 31 Dec 2004
    5
    Medium

    CVE-2004-2283

    Last Modified: 16 Apr 2026

    Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache.

    Published: 31 Dec 2004
    10
    Critical

    CVE-2004-2284

    Last Modified: 16 Apr 2026

    The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.

    Published: 31 Dec 2004
    Unknown

    CVE-2004-2285

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-2022. Reason: This candidate is a duplicate of CVE-2004-2022. Notes: All CVE users should reference CVE-2004-2022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2293

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) eid parameter or (2) query parameter to the Encyclopedia module, (3) preview_review function in the Reviews module as demonstrated by the url, cover, rlanguage, and hits parameters, or (4) savecomment function in the Reviews module, as demonstrated using the uname parameter. NOTE: the Faq/categories and Encyclopedia/ltr issues are already covered by CVE-2005-1023.

    Published: 31 Dec 2004
    3.6
    Low

    CVE-2004-2303

    Last Modified: 16 Apr 2026

    MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2304

    Last Modified: 16 Apr 2026

    Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.

    Published: 31 Dec 2004
    8.4
    High

    CVE-2004-2339

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2347

    Last Modified: 16 Apr 2026

    blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile requests.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2363

    Last Modified: 16 Apr 2026

    Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct cross-site scripting (XSS) attacks via hex-encoded tags, which bypass the check for literal "<", ">", "(", and ")" characters, as demonstrated using the limit parameter to forums.php and a variety of other vectors.

    Published: 31 Dec 2004
    7.2
    High

    CVE-2004-2372

    Last Modified: 16 Apr 2026

    Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsrc, and bochsrc.txt cannot be found in a known path. NOTE: some external documents recommend that Bochs be installed setuid root, so this should be treated as a vulnerability.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2376

    Last Modified: 16 Apr 2026

    Buffer overflow in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request with a long attfile attribute.

    Published: 31 Dec 2004
    7.5
    High

    CVE-2004-2393

    Last Modified: 16 Apr 2026

    Java Secure Socket Extension (JSSE) 1.0.3 through 1.0.3_2 does not properly validate the certificate chain of a client or server, which allows remote attackers to falsely authenticate peers for SSL/TLS.

    Published: 31 Dec 2004
    2.1
    Low

    CVE-2004-2394

    Last Modified: 16 Apr 2026

    Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.

    Published: 31 Dec 2004
    4.3
    Medium

    CVE-2004-2402

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board parameter is affected, but this is incorrect.

    Published: 31 Dec 2004