CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2004-1380

    Last Modified: 16 Apr 2026

    Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."

    Published: 20 Oct 2004
    7.5
    High

    CVE-2004-1619

    Last Modified: 16 Apr 2026

    Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.

    Published: 20 Oct 2004
    7.5
    High

    CVE-2004-0805

    Last Modified: 16 Apr 2026

    Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.

    Published: 20 Oct 2004
    7.2
    High

    CVE-2004-0834

    Last Modified: 16 Apr 2026

    Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.

    Published: 20 Oct 2004
    2.1
    Low

    CVE-2004-0966

    Last Modified: 16 Apr 2026

    The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

    Published: 20 Oct 2004
    2.1
    Low

    CVE-2004-0974

    Last Modified: 16 Apr 2026

    The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

    Published: 20 Oct 2004
    Unknown

    CVE-2004-0973

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0457. Reason: This candidate is a reservation duplicate of CVE-2004-0457. Notes: All CVE users should reference CVE-2004-0457 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Oct 2004
    2.1
    Low

    CVE-2004-0969

    Last Modified: 16 Apr 2026

    The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

    Published: 20 Oct 2004
    7.5
    High

    CVE-2005-0206

    Last Modified: 16 Apr 2026

    The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.

    Published: 20 Oct 2004
    5
    Medium

    CVE-2004-1618

    Last Modified: 16 Apr 2026

    Vypress Tonecast 1.3 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed mp2 stream.

    Published: 19 Oct 2004
    7.2
    High

    CVE-2004-1353

    Last Modified: 16 Apr 2026

    Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.

    Published: 19 Oct 2004
    4.1
    Medium

    CVE-2006-5871

    Last Modified: 23 Apr 2026

    smbfs in Linux kernel 2.6.8 and other versions, and 2.4.x before 2.4.34, when UNIX extensions are enabled, ignores certain mount options, which could cause clients to use server-specified uid, gid and mode settings.

    Published: 19 Oct 2004
    10
    Critical

    CVE-2004-0891

    Last Modified: 16 Apr 2026

    Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.

    Published: 19 Oct 2004
    4.3
    Medium

    CVE-2004-1621

    Last Modified: 16 Apr 2026

    NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature

    Published: 18 Oct 2004
    5
    Medium

    CVE-2004-1617

    Last Modified: 16 Apr 2026

    Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and (2) a large tag name in an element that is not terminated, as demonstrated by mangleme. NOTE: a followup suggests that the relevant trigger for this issue is the large COLS value.

    Published: 18 Oct 2004
    5
    Medium

    CVE-2004-1616

    Last Modified: 16 Apr 2026

    Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.

    Published: 18 Oct 2004
    7.5
    High

    CVE-2004-1608

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.

    Published: 18 Oct 2004
    6.4
    Medium

    CVE-2004-1606

    Last Modified: 16 Apr 2026

    slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie.

    Published: 18 Oct 2004
    5.5
    Medium

    CVE-2004-1603

    Last Modified: 16 Apr 2026

    cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.

    Published: 18 Oct 2004
    5
    Medium

    CVE-2004-1607

    Last Modified: 16 Apr 2026

    slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.

    Published: 18 Oct 2004
    7.5
    High

    CVE-2004-1610

    Last Modified: 16 Apr 2026

    SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.

    Published: 18 Oct 2004
    5.1
    Medium

    CVE-2004-1611

    Last Modified: 16 Apr 2026

    SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.

    Published: 18 Oct 2004
    5
    Medium

    CVE-2004-1612

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.

    Published: 18 Oct 2004
    5
    Medium

    CVE-2004-1614

    Last Modified: 16 Apr 2026

    Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.

    Published: 18 Oct 2004
    2.6
    Low

    CVE-2004-1615

    Last Modified: 16 Apr 2026

    Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web page or HTML email that contains a TBODY tag with a large COL SPAN value, as demonstrated by mangleme.

    Published: 18 Oct 2004
    5
    Medium

    CVE-2004-1609

    Last Modified: 16 Apr 2026

    SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.

    Published: 18 Oct 2004
    5
    Medium

    CVE-2004-1613

    Last Modified: 16 Apr 2026

    Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.

    Published: 18 Oct 2004
    5
    Medium

    CVE-2004-0844

    Last Modified: 16 Apr 2026

    Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."

    Published: 16 Oct 2004
    10
    Critical

    CVE-2004-0840

    Last Modified: 16 Apr 2026

    The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.

    Published: 16 Oct 2004
    5
    Medium

    CVE-2004-0843

    Last Modified: 16 Apr 2026

    Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."

    Published: 16 Oct 2004
    7.5
    High

    CVE-2004-0846

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.

    Published: 16 Oct 2004
    5
    Medium

    CVE-2003-0718

    Last Modified: 16 Apr 2026

    The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.

    Published: 16 Oct 2004
    7.5
    High

    CVE-2004-0206

    Last Modified: 16 Apr 2026

    Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.

    Published: 16 Oct 2004
    2.1
    Low

    CVE-2004-0207

    Last Modified: 16 Apr 2026

    "Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.

    Published: 16 Oct 2004
    10
    Critical

    CVE-2004-0214

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.

    Published: 16 Oct 2004
    7.5
    High

    CVE-2004-0569

    Last Modified: 16 Apr 2026

    The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.

    Published: 16 Oct 2004
    10
    Critical

    CVE-2004-0574

    Last Modified: 16 Apr 2026

    The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.

    Published: 16 Oct 2004
    10
    Critical

    CVE-2004-0575

    Last Modified: 16 Apr 2026

    Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.

    Published: 16 Oct 2004
    5
    Medium

    CVE-2004-1600

    Last Modified: 16 Apr 2026

    index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which reveals the path in an error message.

    Published: 16 Oct 2004
    7.5
    High

    CVE-2004-1601

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.

    Published: 16 Oct 2004
    4.3
    Medium

    CVE-2004-1599

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.

    Published: 16 Oct 2004
    7.5
    High

    CVE-2004-1638

    Last Modified: 16 Apr 2026

    Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.

    Published: 16 Oct 2004
    7.2
    High

    CVE-2004-0208

    Last Modified: 16 Apr 2026

    The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.

    Published: 16 Oct 2004
    10
    Critical

    CVE-2004-0209

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."

    Published: 16 Oct 2004
    2.1
    Low

    CVE-2004-0211

    Last Modified: 16 Apr 2026

    The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.

    Published: 16 Oct 2004
    10
    Critical

    CVE-2004-0572

    Last Modified: 16 Apr 2026

    Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.

    Published: 16 Oct 2004
    7.8
    High

    CVE-2004-0774

    Last Modified: 16 Apr 2026

    RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length header set to -1.

    Published: 16 Oct 2004
    6.4
    Medium

    CVE-2004-0845

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.

    Published: 16 Oct 2004
    10
    Critical

    CVE-2004-0216

    Last Modified: 16 Apr 2026

    Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.

    Published: 16 Oct 2004
    5
    Medium

    CVE-2004-1602

    Last Modified: 16 Apr 2026

    ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.

    Published: 15 Oct 2004