CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-1350

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.

    Published: 30 Oct 2004
    5
    Medium

    CVE-2004-0922

    Last Modified: 16 Apr 2026

    AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.

    Published: 28 Oct 2004
    10
    Critical

    CVE-2004-0962

    Last Modified: 16 Apr 2026

    Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switching.

    Published: 28 Oct 2004
    7.2
    High

    CVE-2004-0510

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.

    Published: 28 Oct 2004
    2.1
    Low

    CVE-2004-0511

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null dereference.

    Published: 28 Oct 2004
    2.1
    Low

    CVE-2004-0512

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a core dump.

    Published: 28 Oct 2004
    10
    Critical

    CVE-2004-0926

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.

    Published: 28 Oct 2004
    7.5
    High

    CVE-2004-0921

    Last Modified: 16 Apr 2026

    AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.

    Published: 28 Oct 2004
    5
    Medium

    CVE-2004-0924

    Last Modified: 16 Apr 2026

    NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.

    Published: 28 Oct 2004
    5
    Medium

    CVE-2004-0925

    Last Modified: 16 Apr 2026

    Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.

    Published: 28 Oct 2004
    5
    Medium

    CVE-2004-0988

    Last Modified: 16 Apr 2026

    Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.

    Published: 28 Oct 2004
    5
    Medium

    CVE-2004-0927

    Last Modified: 16 Apr 2026

    ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.

    Published: 28 Oct 2004
    4.9
    Medium

    CVE-2004-2660

    Last Modified: 16 Apr 2026

    Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.10 allows local users to cause a denial of service (memory consumption) via certain O_DIRECT (direct IO) write requests.

    Published: 28 Oct 2004
    5
    Medium

    CVE-2005-1061

    Last Modified: 16 Apr 2026

    The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."

    Published: 28 Oct 2004
    7.2
    High

    CVE-2004-0965

    Last Modified: 16 Apr 2026

    stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.

    Published: 26 Oct 2004
    7.5
    High

    CVE-2004-0816

    Last Modified: 16 Apr 2026

    Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.

    Published: 26 Oct 2004
    10
    Critical

    CVE-2004-0985

    Last Modified: 16 Apr 2026

    Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to write to a .hta file that is interpreted in the Local Zone by HTML Help.

    Published: 26 Oct 2004
    7.2
    High

    CVE-2004-0887

    Last Modified: 16 Apr 2026

    SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which allows local users to gain root privileges.

    Published: 26 Oct 2004
    10
    Critical

    CVE-2004-0889

    Last Modified: 16 Apr 2026

    Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.

    Published: 26 Oct 2004
    10
    Critical

    CVE-2004-0929

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the OJPEGVSetField function in tif_ojpeg.c for libtiff 3.6.1 and earlier, when compiled with the OJPEG_SUPPORT (old JPEG support) option, allows remote attackers to execute arbitrary code via a malformed TIFF image.

    Published: 26 Oct 2004
    10
    Critical

    CVE-2004-1636

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.

    Published: 26 Oct 2004
    7.5
    High

    CVE-2004-1637

    Last Modified: 16 Apr 2026

    The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections.

    Published: 26 Oct 2004
    5
    Medium

    CVE-2004-1639

    Last Modified: 16 Apr 2026

    Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.

    Published: 26 Oct 2004
    10
    Critical

    CVE-2004-0989

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.

    Published: 26 Oct 2004
    10
    Critical

    CVE-2004-0990

    Last Modified: 16 Apr 2026

    Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

    Published: 26 Oct 2004
    5
    Medium

    CVE-2004-1633

    Last Modified: 16 Apr 2026

    process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenticated users to modify the keywords in a bug via the keywordaction parameter.

    Published: 25 Oct 2004
    5
    Medium

    CVE-2004-1634

    Last Modified: 16 Apr 2026

    show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.

    Published: 25 Oct 2004
    4.3
    Medium

    CVE-2004-1632

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php.

    Published: 25 Oct 2004
    5
    Medium

    CVE-2004-1631

    Last Modified: 16 Apr 2026

    Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.

    Published: 25 Oct 2004
    4.3
    Medium

    CVE-2004-1630

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url parameter.

    Published: 25 Oct 2004
    5
    Medium

    CVE-2004-1635

    Last Modified: 16 Apr 2026

    Bugzilla 2.17.1 through 2.18rc2 and 2.19 from cvs, when using the insidergroup feature, does not sufficiently protect private attachments when there are changes to the metadata, such as filename, description, MIME type, or review flags, which allows remote authenticated users to obtain sensitive information when (1) viewing the bug activity log or (2) receiving bug change notification mails.

    Published: 24 Oct 2004
    2.1
    Low

    CVE-2004-1382

    Last Modified: 16 Apr 2026

    The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.

    Published: 24 Oct 2004
    7.5
    High

    CVE-2004-1629

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.

    Published: 23 Oct 2004
    9
    Critical

    CVE-2004-1628

    Last Modified: 16 Apr 2026

    Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.

    Published: 23 Oct 2004
    7.5
    High

    CVE-2004-1627

    Last Modified: 16 Apr 2026

    Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.

    Published: 22 Oct 2004
    5
    Medium

    CVE-2004-1625

    Last Modified: 16 Apr 2026

    pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows remote attackers to cause a denial of service by connecting via Remote Desktop and clicking restart or shutdown.

    Published: 22 Oct 2004
    5
    Medium

    CVE-2004-1626

    Last Modified: 16 Apr 2026

    Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.

    Published: 22 Oct 2004
    5
    Medium

    CVE-2004-1623

    Last Modified: 16 Apr 2026

    The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.

    Published: 22 Oct 2004
    7.2
    High

    CVE-2004-1624

    Last Modified: 16 Apr 2026

    Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).

    Published: 21 Oct 2004
    Unknown

    CVE-2004-0954

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0597. Reason: This candidate is a reservation duplicate of CVE-2004-0597. Notes: All CVE users should reference CVE-2004-0597 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Oct 2004
    5
    Medium

    CVE-2004-1620

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.

    Published: 21 Oct 2004
    10
    Critical

    CVE-2004-0978

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.

    Published: 21 Oct 2004
    4.6
    Medium

    CVE-2004-0979

    Last Modified: 16 Apr 2026

    Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configuration.

    Published: 21 Oct 2004
    7.5
    High

    CVE-2004-1622

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.

    Published: 21 Oct 2004
    10
    Critical

    CVE-2004-0888

    Last Modified: 16 Apr 2026

    Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.

    Published: 21 Oct 2004
    7.8
    High

    CVE-2004-0940

    Last Modified: 16 Apr 2026

    Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.

    Published: 21 Oct 2004
    2.1
    Low

    CVE-2004-0970

    Last Modified: 16 Apr 2026

    The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.

    Published: 20 Oct 2004
    5
    Medium

    CVE-2004-1381

    Last Modified: 16 Apr 2026

    Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.

    Published: 20 Oct 2004
    10
    Critical

    CVE-2004-0963

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.

    Published: 20 Oct 2004
    10
    Critical

    CVE-2004-0964

    Last Modified: 16 Apr 2026

    Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.

    Published: 20 Oct 2004