CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2004-1228

    Last Modified: 16 Apr 2026

    The install scripts in SugarCRM Sugar Sales 2.0.1c and earlier are not removed after installation, which allows attackers to obtain the MySQL administrative password in cleartext from an installation form, or to cause a denial of service by changing database settings to the default.

    Published: 15 Dec 2004
    7.5
    High

    CVE-2004-1229

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1230

    Last Modified: 16 Apr 2026

    Gadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CTCP packet that contains a 1 as the type and a 4 as the subtype.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1231

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequences in a DCC connection with a CTCP packet that contains a 1 as the type and a 4 as the subtype.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1232

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename.

    Published: 15 Dec 2004
    7.2
    High

    CVE-2004-0893

    Last Modified: 16 Apr 2026

    The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-0901

    Last Modified: 16 Apr 2026

    Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-0994

    Last Modified: 16 Apr 2026

    Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1192

    Last Modified: 16 Apr 2026

    Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.

    Published: 15 Dec 2004
    6.6
    Medium

    CVE-2004-1193

    Last Modified: 16 Apr 2026

    Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalmemory, which restores the running kernel's original SDT ServiceTable.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1194

    Last Modified: 16 Apr 2026

    Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1195

    Last Modified: 16 Apr 2026

    Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.

    Published: 15 Dec 2004
    2.1
    Low

    CVE-2004-1204

    Last Modified: 16 Apr 2026

    FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1215

    Last Modified: 16 Apr 2026

    Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a "message too long" socket error.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1220

    Last Modified: 16 Apr 2026

    Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference.

    Published: 15 Dec 2004
    6.5
    Medium

    CVE-2004-1267

    Last Modified: 16 Apr 2026

    Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1019

    Last Modified: 16 Apr 2026

    The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1139

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1269

    Last Modified: 16 Apr 2026

    lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.

    Published: 15 Dec 2004
    2.1
    Low

    CVE-2004-1268

    Last Modified: 16 Apr 2026

    lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.

    Published: 15 Dec 2004
    2.1
    Low

    CVE-2004-1270

    Last Modified: 16 Apr 2026

    lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1287

    Last Modified: 16 Apr 2026

    Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1392

    Last Modified: 16 Apr 2026

    PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.

    Published: 15 Dec 2004
    7.2
    High

    CVE-2004-1138

    Last Modified: 16 Apr 2026

    VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1140

    Last Modified: 16 Apr 2026

    Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (application hang) and possibly fill available disk space via an invalid RTP timestamp.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1141

    Last Modified: 16 Apr 2026

    The HTTP dissector in Ethereal 0.10.1 through 0.10.7 allows remote attackers to cause a denial of service (application crash) via a certain packet that causes the dissector to access previously-freed memory.

    Published: 15 Dec 2004
    10
    Critical

    CVE-2004-1065

    Last Modified: 16 Apr 2026

    Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.

    Published: 15 Dec 2004
    5
    Medium

    CVE-2004-1142

    Last Modified: 16 Apr 2026

    Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.

    Published: 15 Dec 2004
    6.4
    Medium

    CVE-2004-1056

    Last Modified: 16 Apr 2026

    Direct Rendering Manager (DRM) driver in Linux kernel 2.6 does not properly check the DMA lock, which could allow remote attackers or local users to cause a denial of service (X Server crash) and possibly modify the video output.

    Published: 14 Dec 2004
    10
    Critical

    CVE-2004-1137

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.

    Published: 14 Dec 2004
    7.5
    High

    CVE-2004-1176

    Last Modified: 16 Apr 2026

    Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 13 Dec 2004
    10
    Critical

    CVE-2004-1152

    Last Modified: 16 Apr 2026

    Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.

    Published: 12 Dec 2004
    Unknown

    CVE-2004-1159

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1122, CVE-2004-1314. Reason: this was an out-of-band assignment duplicate intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2004-1122 and CVE-2004-1314 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Dec 2004
    7.5
    High

    CVE-2004-1155

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one window into another window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. NOTE: later research shows that Internet Explorer 7 on Windows XP SP2 is also vulnerable.

    Published: 10 Dec 2004
    7.5
    High

    CVE-2004-1160

    Last Modified: 16 Apr 2026

    Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

    Published: 10 Dec 2004
    7.5
    High

    CVE-2004-1161

    Last Modified: 16 Apr 2026

    rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.

    Published: 10 Dec 2004
    5
    Medium

    CVE-2004-1164

    Last Modified: 16 Apr 2026

    The lock manager in Cisco CNS Network Registrar 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (process crash) via a certain "unexpected packet sequence."

    Published: 10 Dec 2004
    5
    Medium

    CVE-2004-1167

    Last Modified: 16 Apr 2026

    mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite arbitrary files via a symlink attack.

    Published: 10 Dec 2004
    10
    Critical

    CVE-2004-1168

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code via a long Overwrite header.

    Published: 10 Dec 2004
    2.1
    Low

    CVE-2004-1171

    Last Modified: 16 Apr 2026

    KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.

    Published: 10 Dec 2004
    5
    Medium

    CVE-2004-0915

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote attackers to gain sensitive information.

    Published: 10 Dec 2004
    4.3
    Medium

    CVE-2004-1059

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in mnoGoSearch 3.2.26 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) next and (2) prev result search pages, and the (3) extended and (4) simple search forms.

    Published: 10 Dec 2004
    10
    Critical

    CVE-2004-1067

    Last Modified: 16 Apr 2026

    Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.

    Published: 10 Dec 2004
    7.5
    High

    CVE-2004-1122

    Last Modified: 16 Apr 2026

    Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314.

    Published: 10 Dec 2004
    7.5
    High

    CVE-2004-1157

    Last Modified: 16 Apr 2026

    Opera 7.x up to 7.54, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

    Published: 10 Dec 2004
    7.5
    High

    CVE-2004-1162

    Last Modified: 16 Apr 2026

    The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.

    Published: 10 Dec 2004
    5
    Medium

    CVE-2004-1163

    Last Modified: 16 Apr 2026

    Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets.

    Published: 10 Dec 2004
    10
    Critical

    CVE-2004-1170

    Last Modified: 16 Apr 2026

    a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

    Published: 10 Dec 2004
    5
    Medium

    CVE-2004-1169

    Last Modified: 16 Apr 2026

    MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that does not exist, followed by two carriage returns, which causes a NULL dereference.

    Published: 10 Dec 2004
    10
    Critical

    CVE-2004-0993

    Last Modified: 16 Apr 2026

    Buffer overflow in hpsockd before 0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code.

    Published: 10 Dec 2004