CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-1096

    Last Modified: 16 Apr 2026

    Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

    Published: 1 Dec 2004
    7.5
    High

    CVE-2004-1098

    Last Modified: 16 Apr 2026

    MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1099

    Last Modified: 16 Apr 2026

    Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remote attackers to bypass authentication and gain unauthorized access via a "cryptographically correct" certificate with valid fields such as the username.

    Published: 1 Dec 2004
    5.8
    Medium

    CVE-2004-1101

    Last Modified: 16 Apr 2026

    mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive pathname information in the resulting error message, and execute a cross-site scripting (XSS) attack via an HTTP request that contains a / (backslash) and arbitrary webscript before the requested file, which leaks the pathname and does not quote the script in the resulting Visual Basic error message.

    Published: 1 Dec 2004
    6.8
    Medium

    CVE-2004-1106

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include parameter in index.php.

    Published: 1 Dec 2004
    2.1
    Low

    CVE-2004-1108

    Last Modified: 16 Apr 2026

    qpkg in Gentoolkit 0.2.0_pre10 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary directory.

    Published: 1 Dec 2004
    5
    Medium

    CVE-2004-1109

    Last Modified: 16 Apr 2026

    The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.

    Published: 1 Dec 2004
    5.1
    Medium

    CVE-2004-1112

    Last Modified: 16 Apr 2026

    The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.

    Published: 1 Dec 2004
    7.2
    High

    CVE-2004-1115

    Last Modified: 16 Apr 2026

    The init scripts in Search for Extraterrestrial Intelligence (SETI) project 3.08-r3 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.

    Published: 1 Dec 2004
    7.2
    High

    CVE-2004-1352

    Last Modified: 16 Apr 2026

    Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1008

    Last Modified: 16 Apr 2026

    Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1015

    Last Modified: 16 Apr 2026

    Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2004-1011.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1113

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) sender or (2) recipient e-mail addresses.

    Published: 1 Dec 2004
    7.2
    High

    CVE-2004-1079

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) ncplogin and (2) ncpmap in nwclient.c for ncpfs 2.2.4, and possibly other versions, may allow local users to gain privileges via a long -T option.

    Published: 1 Dec 2004
    5
    Medium

    CVE-2004-1103

    Last Modified: 16 Apr 2026

    MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version.

    Published: 1 Dec 2004
    6.8
    Medium

    CVE-2004-1100

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter.

    Published: 1 Dec 2004
    5
    Medium

    CVE-2004-1102

    Last Modified: 16 Apr 2026

    MailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested file exists or not, which allows remote attackers to gain sensitive information.

    Published: 1 Dec 2004
    2.1
    Low

    CVE-2004-1110

    Last Modified: 16 Apr 2026

    The mtink status monitor before 1.0.5 for Epson printers allows local users to overwrite arbitrary files via a symlink attack on the epson temporary file.

    Published: 1 Dec 2004
    2.1
    Low

    CVE-2004-1107

    Last Modified: 16 Apr 2026

    dispatch-conf in Portage 2.0.51-r2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 1 Dec 2004
    7.2
    High

    CVE-2004-1117

    Last Modified: 16 Apr 2026

    The init scripts in ChessBrain 20407 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1118

    Last Modified: 16 Apr 2026

    Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1119

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist file.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1120

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.

    Published: 1 Dec 2004
    7.2
    High

    CVE-2004-1116

    Last Modified: 16 Apr 2026

    The init scripts in Great Internet Mersenne Prime Search (GIMPS) 23.9 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-0953

    Last Modified: 16 Apr 2026

    Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long username.

    Published: 1 Dec 2004
    10
    Critical

    CVE-2004-1011

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.

    Published: 1 Dec 2004
    1.2
    Low

    CVE-2004-1069

    Last Modified: 16 Apr 2026

    Race condition in SELinux 2.6.x through 2.6.9 allows local users to cause a denial of service (kernel crash) via SOCK_SEQPACKET unix domain sockets, which are not properly handled in the sock_dgram_sendmsg function.

    Published: 1 Dec 2004
    6.8
    Medium

    CVE-2004-1075

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject arbitrary HTML and web script via a malformed URL, which is not properly cleansed when generating an error message.

    Published: 1 Dec 2004
    7.5
    High

    CVE-2004-1104

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page that contains a BASE element that points to the legitimate site, followed by an anchor (a) element with an empty "href" attribute, and a FORM whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.

    Published: 1 Dec 2004
    5
    Medium

    CVE-2004-1111

    Last Modified: 16 Apr 2026

    Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input queue size.

    Published: 1 Dec 2004
    5
    Medium

    CVE-2004-1014

    Last Modified: 16 Apr 2026

    statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.

    Published: 1 Dec 2004
    5
    Medium

    CVE-2004-1771

    Last Modified: 16 Apr 2026

    Scalable OGo (SOGo) 1.0 allows remote authenticated users to bypass intended permissions and view private appointments of other users.

    Published: 30 Nov 2004
    10
    Critical

    CVE-2004-1017

    Last Modified: 16 Apr 2026

    Multiple "overflows" in the io_edgeport driver for Linux kernel 2.4.x have unknown impact and unknown attack vectors.

    Published: 26 Nov 2004
    2.1
    Low

    CVE-2004-1030

    Last Modified: 16 Apr 2026

    fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message.

    Published: 24 Nov 2004
    7.2
    High

    CVE-2004-1031

    Last Modified: 16 Apr 2026

    fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as /proc/self/cmdline or /proc/self/environ.

    Published: 24 Nov 2004
    5
    Medium

    CVE-2004-0810

    Last Modified: 16 Apr 2026

    Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.

    Published: 24 Nov 2004
    5
    Medium

    CVE-2004-0950

    Last Modified: 16 Apr 2026

    NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, a "custom" HELO request.

    Published: 24 Nov 2004
    10
    Critical

    CVE-2004-1053

    Last Modified: 16 Apr 2026

    Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certain HTTP headers in an HTTP response, which lead to a buffer overflow.

    Published: 24 Nov 2004
    7.5
    High

    CVE-2004-1021

    Last Modified: 16 Apr 2026

    iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attackers to execute programs and send e-mail via alarms.

    Published: 24 Nov 2004
    2.1
    Low

    CVE-2004-1032

    Last Modified: 16 Apr 2026

    fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.

    Published: 24 Nov 2004
    2.1
    Low

    CVE-2004-1033

    Last Modified: 16 Apr 2026

    Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.

    Published: 24 Nov 2004
    9.3
    Critical

    CVE-2004-1029

    Last Modified: 16 Apr 2026

    The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

    Published: 24 Nov 2004
    6.8
    Medium

    CVE-2004-1055

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.

    Published: 24 Nov 2004
    5
    Medium

    CVE-2004-2479

    Last Modified: 16 Apr 2026

    Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.

    Published: 23 Nov 2004
    10
    Critical

    CVE-2004-0946

    Last Modified: 16 Apr 2026

    rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.

    Published: 22 Nov 2004
    7.5
    High

    CVE-2004-0833

    Last Modified: 16 Apr 2026

    Sendmail before 8.12.3 on Debian GNU/Linux, when using sasl and sasl-bin, uses a Sendmail configuration script with a fixed username and password, which could allow remote attackers to use Sendmail as an open mail relay and send spam messages.

    Published: 19 Nov 2004
    7.5
    High

    CVE-2004-0932

    Last Modified: 16 Apr 2026

    McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

    Published: 19 Nov 2004
    2.1
    Low

    CVE-2004-0564

    Last Modified: 16 Apr 2026

    Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT designed to run setuid-root." Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer's warnings.

    Published: 19 Nov 2004
    10
    Critical

    CVE-2004-0646

    Last Modified: 16 Apr 2026

    Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.

    Published: 19 Nov 2004
    7.5
    High

    CVE-2004-0933

    Last Modified: 16 Apr 2026

    Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

    Published: 19 Nov 2004