CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-0811

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.

    Published: 24 Sept 2004
    7.5
    High

    CVE-2004-0867

    Last Modified: 16 Apr 2026

    Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.

    Published: 24 Sept 2004
    1.2
    Low

    CVE-2004-0880

    Last Modified: 16 Apr 2026

    getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.

    Published: 24 Sept 2004
    2.1
    Low

    CVE-2004-0881

    Last Modified: 16 Apr 2026

    getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.

    Published: 24 Sept 2004
    4.6
    Medium

    CVE-2004-0907

    Last Modified: 16 Apr 2026

    The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitrary code.

    Published: 24 Sept 2004
    5.1
    Medium

    CVE-2004-0909

    Last Modified: 16 Apr 2026

    Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performing unexpected actions, including installing software, via signed scripts that request enhanced abilities using the enablePrivilege parameter, then modify the meaning of certain security-relevant dialog messages.

    Published: 24 Sept 2004
    7.5
    High

    CVE-2003-1014

    Last Modified: 16 Apr 2026

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use multiple MIME fields with the same name, which may be interpreted differently by mail clients.

    Published: 24 Sept 2004
    7.5
    High

    CVE-2003-1015

    Last Modified: 16 Apr 2026

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.

    Published: 24 Sept 2004
    7.5
    High

    CVE-2004-0162

    Last Modified: 16 Apr 2026

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.

    Published: 24 Sept 2004
    4.3
    Medium

    CVE-2004-0787

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HTML via the form input fields.

    Published: 24 Sept 2004
    7.2
    High

    CVE-2004-0821

    Last Modified: 16 Apr 2026

    The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, which could allow local users to gain privileges.

    Published: 24 Sept 2004
    7.2
    High

    CVE-2004-0850

    Last Modified: 16 Apr 2026

    Star before 1.5_alpha46 does not drop the effective user ID (euid) before calling external programs, which could allow local users to gain privileges by modifying the RSH environment variable to reference a malicious program.

    Published: 24 Sept 2004
    7.5
    High

    CVE-2004-0873

    Last Modified: 16 Apr 2026

    Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.

    Published: 24 Sept 2004
    Unknown

    CVE-2004-0868

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-0866. Reason: This candidate is a duplicate of CVE-2004-0866. Notes: The description for CVE-2004-0866 was inadvertently attached to this issue instead. All CVE users should reference CVE-2004-0866 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Sept 2004
    7.5
    High

    CVE-2003-1016

    Last Modified: 16 Apr 2026

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters, which may be interpreted differently by mail clients.

    Published: 24 Sept 2004
    7.5
    High

    CVE-2004-0053

    Last Modified: 16 Apr 2026

    Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.

    Published: 24 Sept 2004
    6.8
    Medium

    CVE-2004-0875

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.

    Published: 24 Sept 2004
    7.5
    High

    CVE-2004-0687

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.

    Published: 24 Sept 2004
    7.5
    High

    CVE-2004-0750

    Last Modified: 16 Apr 2026

    Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent the all_squash option from being applied.

    Published: 22 Sept 2004
    7.5
    High

    CVE-2004-1697

    Last Modified: 16 Apr 2026

    The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.

    Published: 21 Sept 2004
    5
    Medium

    CVE-2004-1378

    Last Modified: 16 Apr 2026

    The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections.

    Published: 21 Sept 2004
    5
    Medium

    CVE-2004-1696

    Last Modified: 16 Apr 2026

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.

    Published: 21 Sept 2004
    7.5
    High

    CVE-2004-1694

    Last Modified: 16 Apr 2026

    Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access.

    Published: 21 Sept 2004
    5
    Medium

    CVE-2004-1699

    Last Modified: 16 Apr 2026

    SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.

    Published: 21 Sept 2004
    10
    Critical

    CVE-2004-1695

    Last Modified: 16 Apr 2026

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).

    Published: 20 Sept 2004
    5
    Medium

    CVE-2004-0938

    Last Modified: 16 Apr 2026

    FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.

    Published: 20 Sept 2004
    5
    Medium

    CVE-2004-0960

    Last Modified: 16 Apr 2026

    FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.

    Published: 20 Sept 2004
    5
    Medium

    CVE-2004-0961

    Last Modified: 16 Apr 2026

    Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.

    Published: 20 Sept 2004
    7.5
    High

    CVE-2004-1693

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.

    Published: 18 Sept 2004
    4.3
    Medium

    CVE-2004-1692

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.

    Published: 18 Sept 2004
    5
    Medium

    CVE-2004-1691

    Last Modified: 16 Apr 2026

    The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.

    Published: 18 Sept 2004
    4.3
    Medium

    CVE-2004-1690

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Web Server in DNS4Me 3.0.0.4 allows remote attackers to execute arbitrary web script or HTML via the URL.

    Published: 18 Sept 2004
    9.3
    Critical

    CVE-2004-0200

    Last Modified: 16 Apr 2026

    Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

    Published: 17 Sept 2004
    7.5
    High

    CVE-2004-0573

    Last Modified: 16 Apr 2026

    Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.

    Published: 17 Sept 2004
    4.3
    Medium

    CVE-2004-0534

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document.

    Published: 17 Sept 2004
    5
    Medium

    CVE-2004-0849

    Last Modified: 16 Apr 2026

    Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.

    Published: 17 Sept 2004
    5
    Medium

    CVE-2004-0799

    Last Modified: 16 Apr 2026

    The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".

    Published: 17 Sept 2004
    5
    Medium

    CVE-2004-1687

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.

    Published: 16 Sept 2004
    7.5
    High

    CVE-2004-1379

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the DVD subpicture decoder in xine xine-lib 1-rc5 and earlier allows remote attackers to execute arbitrary code via a (1) DVD or (2) MPEG subpicture header where the second field reuses RLE data from the end of the first field.

    Published: 16 Sept 2004
    7.5
    High

    CVE-2004-0801

    Last Modified: 16 Apr 2026

    Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.

    Published: 16 Sept 2004
    5
    Medium

    CVE-2004-0869

    Last Modified: 16 Apr 2026

    Internet Explorer does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."

    Published: 16 Sept 2004
    2.1
    Low

    CVE-2004-1689

    Last Modified: 16 Apr 2026

    sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.

    Published: 16 Sept 2004
    5
    Medium

    CVE-2004-1688

    Last Modified: 16 Apr 2026

    Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sent to port 3103.

    Published: 16 Sept 2004
    5
    Medium

    CVE-2004-0870

    Last Modified: 16 Apr 2026

    KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."

    Published: 16 Sept 2004
    5
    Medium

    CVE-2004-0871

    Last Modified: 16 Apr 2026

    Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."

    Published: 16 Sept 2004
    5
    Medium

    CVE-2004-0872

    Last Modified: 16 Apr 2026

    Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."

    Published: 16 Sept 2004
    7.5
    High

    CVE-2004-0866

    Last Modified: 16 Apr 2026

    Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

    Published: 16 Sept 2004
    10
    Critical

    CVE-2004-1026

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.

    Published: 16 Sept 2004
    10
    Critical

    CVE-2004-1025

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.

    Published: 16 Sept 2004
    7.5
    High

    CVE-2004-1685

    Last Modified: 16 Apr 2026

    SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages.

    Published: 15 Sept 2004