CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-1166

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

    Published: 10 Dec 2004
    5
    Medium

    CVE-2004-1488

    Last Modified: 16 Apr 2026

    wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.

    Published: 10 Dec 2004
    5
    Medium

    CVE-2004-1487

    Last Modified: 16 Apr 2026

    wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.

    Published: 10 Dec 2004
    10
    Critical

    CVE-2004-1018

    Last Modified: 16 Apr 2026

    Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

    Published: 8 Dec 2004
    7.2
    High

    CVE-2004-1076

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large values in the configuration file.

    Published: 8 Dec 2004
    10
    Critical

    CVE-2004-1134

    Last Modified: 16 Apr 2026

    Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.

    Published: 8 Dec 2004
    5
    Medium

    CVE-2004-1020

    Last Modified: 16 Apr 2026

    The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP applications that contain a directory traversal vulnerability in require or include statements, but are otherwise protected by the magic_quotes_gpc mechanism. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

    Published: 8 Dec 2004
    10
    Critical

    CVE-2004-1063

    Last Modified: 16 Apr 2026

    PHP 4.x to 4.3.9, and PHP 5.x to 5.0.2, when running in safe mode on a multithreaded Unix webserver, allows local users to bypass safe_mode_exec_dir restrictions and execute commands outside of the intended safe_mode_exec_dir via shell metacharacters in the current directory name. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

    Published: 8 Dec 2004
    10
    Critical

    CVE-2004-1064

    Last Modified: 16 Apr 2026

    The safe mode checks in PHP 4.x to 4.3.9 and PHP 5.x to 5.0.2 truncate the file path before passing the data to the realpath function, which could allow attackers to bypass safe mode. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

    Published: 8 Dec 2004
    6.8
    Medium

    CVE-2004-1133

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Microsoft W3Who ISAPI (w3who.dll) allow remote attackers to inject arbitrary HTML and web script via (1) HTTP headers such as "Connection" or (2) invalid parameters whose values are echoed in the resulting error message.

    Published: 8 Dec 2004
    5
    Medium

    CVE-2004-1135

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.

    Published: 8 Dec 2004
    7.2
    High

    CVE-2004-1151

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the (1) sys32_ni_syscall and (2) sys32_vm86_warning functions in sys_ia32.c for Linux 2.6.x may allow local attackers to modify kernel memory and gain privileges.

    Published: 8 Dec 2004
    Unknown

    CVE-2004-0890

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reasons: This candidate is a reservation duplicate of another candidate. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 8 Dec 2004
    5
    Medium

    CVE-2004-1136

    Last Modified: 16 Apr 2026

    Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands.

    Published: 8 Dec 2004
    10
    Critical

    CVE-2004-0139

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors.

    Published: 8 Dec 2004
    2.1
    Low

    CVE-2004-0770

    Last Modified: 16 Apr 2026

    romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.

    Published: 8 Dec 2004
    2.1
    Low

    CVE-2004-1016

    Last Modified: 16 Apr 2026

    The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

    Published: 8 Dec 2004
    4.3
    Medium

    CVE-2004-1156

    Last Modified: 16 Apr 2026

    Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

    Published: 8 Dec 2004
    7.5
    High

    CVE-2004-1158

    Last Modified: 16 Apr 2026

    Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

    Published: 8 Dec 2004
    2.1
    Low

    CVE-2004-1335

    Last Modified: 16 Apr 2026

    Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.

    Published: 8 Dec 2004
    10
    Critical

    CVE-2004-1351

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.

    Published: 7 Dec 2004
    Unknown

    CVE-2004-0874

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1123. Reason: This candidate is a reservation duplicate of CVE-2004-1123. Notes: All CVE users should reference CVE-2004-1123 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Dec 2004
    10
    Critical

    CVE-2004-1127

    Last Modified: 16 Apr 2026

    Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command.

    Published: 5 Dec 2004
    5
    Medium

    CVE-2004-0956

    Last Modified: 16 Apr 2026

    MySQL before 4.0.20 allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closing double quote.

    Published: 5 Dec 2004
    10
    Critical

    CVE-2004-0987

    Last Modified: 16 Apr 2026

    Buffer overflow in the process_menu function in yardradius 1.0.20 allows remote attackers to execute arbitrary code.

    Published: 5 Dec 2004
    3.6
    Low

    CVE-2004-1066

    Last Modified: 16 Apr 2026

    The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory. NOTE: this candidate might be SPLIT into 2 separate items in the future.

    Published: 5 Dec 2004
    10
    Critical

    CVE-2004-1128

    Last Modified: 16 Apr 2026

    Buffer overflow in CMailCOM.dll in CMailServer 5.2 allows remote attackers to execute arbitrary code via an attachment with a long filename.

    Published: 5 Dec 2004
    10
    Critical

    CVE-2004-1129

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter.

    Published: 5 Dec 2004
    6.8
    Medium

    CVE-2004-1130

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.asp in CMailServer 5.2 allows remote attackers to execute arbitrary web script or HTML via personal information fields, such as (1) username, (2) name, or (3) comments.

    Published: 5 Dec 2004
    5
    Medium

    CVE-2004-1123

    Last Modified: 16 Apr 2026

    Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.

    Published: 5 Dec 2004
    7.5
    High

    CVE-2004-1165

    Last Modified: 16 Apr 2026

    Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

    Published: 5 Dec 2004
    10
    Critical

    CVE-2003-1208

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Oracle 9i 9 before 9.2.0.3 allow local users to execute arbitrary code by (1) setting the TIME_ZONE session parameter to a long value, or providing long parameters to the (2) NUMTOYMINTERVAL, (3) NUMTODSINTERVAL or (4) FROM_TZ functions.

    Published: 3 Dec 2004
    7.5
    High

    CVE-2004-1083

    Last Modified: 16 Apr 2026

    Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.

    Published: 3 Dec 2004
    5
    Medium

    CVE-2006-0481

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.

    Published: 3 Dec 2004
    5
    Medium

    CVE-2004-1084

    Last Modified: 16 Apr 2026

    Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.

    Published: 2 Dec 2004
    2.1
    Low

    CVE-2004-1085

    Last Modified: 16 Apr 2026

    Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.

    Published: 2 Dec 2004
    7.5
    High

    CVE-2004-1086

    Last Modified: 16 Apr 2026

    Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.

    Published: 2 Dec 2004
    2.1
    Low

    CVE-2004-1087

    Last Modified: 16 Apr 2026

    Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.

    Published: 2 Dec 2004
    7.5
    High

    CVE-2004-1088

    Last Modified: 16 Apr 2026

    Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.

    Published: 2 Dec 2004
    4.6
    Medium

    CVE-2004-1089

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.

    Published: 2 Dec 2004
    2.1
    Low

    CVE-2004-1081

    Last Modified: 16 Apr 2026

    The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.

    Published: 2 Dec 2004
    9.3
    Critical

    CVE-2004-1114

    Last Modified: 16 Apr 2026

    Buffer overflow in the handling of command line arguments in Skype 1.0.x.94 through 1.0.x.98 allows remote attackers to execute arbitrary code via a callto:// URL with a long non-existent username, a different vulnerability than CVE-2004-1777.

    Published: 1 Dec 2004
    2.1
    Low

    CVE-2004-0996

    Last Modified: 16 Apr 2026

    main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1012

    Last Modified: 16 Apr 2026

    The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1097

    Last Modified: 16 Apr 2026

    Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.

    Published: 1 Dec 2004
    5
    Medium

    CVE-2004-1105

    Last Modified: 16 Apr 2026

    Nortel Networks Contivity VPN Client displays a different error message depending on whether the username is valid or invalid, which could allow remote attackers to gain sensitive information.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1013

    Last Modified: 16 Apr 2026

    The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1080

    Last Modified: 16 Apr 2026

    The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1094

    Last Modified: 16 Apr 2026

    Buffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2) the Restore Backup function in CheckMark Software Payroll 2004/2005 3.9.6 and earlier, (3) CheckMark MultiLedger before 7.0.2, (4) dtSearch 6.x and 7.x, (5) mcupdmgr.exe and mghtml.exe in McAfee VirusScan 10 Build 10.0.21 and earlier, (6) IBM Lotus Notes before 6.5.5, and other products. NOTE: it is unclear whether this is the same vulnerability as CVE-2004-0575, although the data manipulations are the same.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1095

    Last Modified: 16 Apr 2026

    Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.

    Published: 1 Dec 2004