CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2004-1686

    Last Modified: 16 Apr 2026

    Internet Explorer 6.0 in Windows XP SP2 allows remote attackers to bypass the Information Bar prompt for ActiveX and Javascript via an XHTML page that contains an Internet Explorer formatted comment between the DOCTYPE tag and the HTML tag, as demonstrated using the DesignScience MathPlayer ActiveX plugin.

    Published: 15 Sept 2004
    7.5
    High

    CVE-2004-0688

    Last Modified: 16 Apr 2026

    Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file.

    Published: 15 Sept 2004
    7.5
    High

    CVE-2004-0782

    Last Modified: 16 Apr 2026

    Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).

    Published: 15 Sept 2004
    7.5
    High

    CVE-2004-0783

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).

    Published: 15 Sept 2004
    7.8
    High

    CVE-2004-0747

    Last Modified: 16 Apr 2026

    Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.

    Published: 15 Sept 2004
    5
    Medium

    CVE-2004-0788

    Last Modified: 16 Apr 2026

    Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.

    Published: 15 Sept 2004
    5
    Medium

    CVE-2004-0809

    Last Modified: 16 Apr 2026

    The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.

    Published: 15 Sept 2004
    10
    Critical

    CVE-2004-0914

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.

    Published: 15 Sept 2004
    5
    Medium

    CVE-2004-0786

    Last Modified: 16 Apr 2026

    The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.

    Published: 15 Sept 2004
    5
    Medium

    CVE-2004-0958

    Last Modified: 16 Apr 2026

    php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

    Published: 15 Sept 2004
    2.1
    Low

    CVE-2004-0959

    Last Modified: 16 Apr 2026

    rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain MIME header that causes the "$_FILES" array to be modified.

    Published: 15 Sept 2004
    4.6
    Medium

    CVE-2004-0690

    Last Modified: 16 Apr 2026

    The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.

    Published: 14 Sept 2004
    5
    Medium

    CVE-2004-0841

    Last Modified: 16 Apr 2026

    Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."

    Published: 14 Sept 2004
    7.5
    High

    CVE-2004-0842

    Last Modified: 16 Apr 2026

    Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."

    Published: 14 Sept 2004
    7.5
    High

    CVE-2004-0699

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.

    Published: 14 Sept 2004
    7.5
    High

    CVE-2004-0775

    Last Modified: 16 Apr 2026

    Buffer overflow in WIDCOMM Bluetooth Connectivity Software, as used in products such as BTStackServer 1.3.2.7 and 1.4.2.10, Windows XP and Windows 98 with MSI Bluetooth Dongles, and HP IPAQ 5450 running WinCE 3.0, allows remote attackers to execute arbitrary code via certain service requests.

    Published: 14 Sept 2004
    7.2
    High

    CVE-2004-0793

    Last Modified: 16 Apr 2026

    The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.

    Published: 14 Sept 2004
    7.2
    High

    CVE-2004-0831

    Last Modified: 16 Apr 2026

    McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges.

    Published: 14 Sept 2004
    4.3
    Medium

    CVE-2004-0781

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.

    Published: 14 Sept 2004
    2.1
    Low

    CVE-2004-0797

    Last Modified: 16 Apr 2026

    The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).

    Published: 14 Sept 2004
    2.1
    Low

    CVE-2004-0838

    Last Modified: 16 Apr 2026

    Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.

    Published: 13 Sept 2004
    5
    Medium

    CVE-2004-1680

    Last Modified: 16 Apr 2026

    application.cgi in the Pingtel Xpressa handset running firmware 2.1.11.24 allows remote authenticated users to cause a denial of service (VxWorks OS crash) via a long HTTP GET request, possibly triggering a buffer overflow.

    Published: 13 Sept 2004
    5
    Medium

    CVE-2004-1678

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.

    Published: 13 Sept 2004
    3.7
    Low

    CVE-2004-1683

    Last Modified: 16 Apr 2026

    A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.

    Published: 13 Sept 2004
    5
    Medium

    CVE-2004-1684

    Last Modified: 16 Apr 2026

    Zyxel P681 running ZyNOS Vt020225a contains portions of memory in an ARP request, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 13 Sept 2004
    5
    Medium

    CVE-2004-0808

    Last Modified: 16 Apr 2026

    The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UAS_CHANGE request with a length value that is larger than the number of structures that are provided.

    Published: 13 Sept 2004
    5
    Medium

    CVE-2004-0807

    Last Modified: 16 Apr 2026

    Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.

    Published: 13 Sept 2004
    5
    Medium

    CVE-2004-1677

    Last Modified: 16 Apr 2026

    pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.

    Published: 12 Sept 2004
    7.5
    High

    CVE-2004-1676

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message.

    Published: 12 Sept 2004
    5
    Medium

    CVE-2004-1675

    Last Modified: 16 Apr 2026

    Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.

    Published: 11 Sept 2004
    5
    Medium

    CVE-2004-0829

    Last Modified: 16 Apr 2026

    smbd in Samba before 2.2.11 allows remote attackers to cause a denial of service (daemon crash) by sending a FindNextPrintChangeNotify request without a previous FindFirstPrintChangeNotify, as demonstrated by the SMB client in Windows XP SP2.

    Published: 10 Sept 2004
    5
    Medium

    CVE-2004-0751

    Last Modified: 16 Apr 2026

    The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).

    Published: 10 Sept 2004
    4.3
    Medium

    CVE-2004-1669

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.

    Published: 10 Sept 2004
    7.5
    High

    CVE-2004-1670

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary files via a ....// (doubled dot dot) in the folderold or folder parameters to folders.html.

    Published: 10 Sept 2004
    7.5
    High

    CVE-2004-1668

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters.

    Published: 10 Sept 2004
    2.1
    Low

    CVE-2004-1237

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors.

    Published: 10 Sept 2004
    5
    Medium

    CVE-2004-0830

    Last Modified: 16 Apr 2026

    The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain malformed packet.

    Published: 9 Sept 2004
    5
    Medium

    CVE-2004-1667

    Last Modified: 16 Apr 2026

    Off-by-one error in Halo Combat Evolved 1.04 and earlier allows remote attackers to cause a denial of service (server crash) via a long client response.

    Published: 9 Sept 2004
    7.2
    High

    CVE-2004-0806

    Last Modified: 16 Apr 2026

    cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.

    Published: 9 Sept 2004
    2.1
    Low

    CVE-2004-0851

    Last Modified: 16 Apr 2026

    The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 8 Sept 2004
    7.2
    High

    CVE-2004-0822

    Last Modified: 16 Apr 2026

    Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbitrary code via a certain environment variable.

    Published: 7 Sept 2004
    7.5
    High

    CVE-2004-0823

    Last Modified: 16 Apr 2026

    OpenLDAP 1.0 through 2.1.19, as used in Apple Mac OS 10.3.4 and 10.3.5 and possibly other operating systems, may allow certain authentication schemes to use hashed (crypt) passwords in the userPassword attribute as if they were plaintext passwords, which allows remote attackers to re-use hashed passwords without decrypting them.

    Published: 7 Sept 2004
    1.2
    Low

    CVE-2004-0814

    Last Modified: 16 Apr 2026

    Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.

    Published: 7 Sept 2004
    5
    Medium

    CVE-2004-1348

    Last Modified: 16 Apr 2026

    Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).

    Published: 6 Sept 2004
    4.3
    Medium

    CVE-2004-1665

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.

    Published: 5 Sept 2004
    5
    Medium

    CVE-2004-1664

    Last Modified: 16 Apr 2026

    Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430.

    Published: 5 Sept 2004
    5
    Medium

    CVE-2004-1663

    Last Modified: 16 Apr 2026

    Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.

    Published: 4 Sept 2004
    10
    Critical

    CVE-2004-0902

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.

    Published: 4 Sept 2004
    6.5
    Medium

    CVE-2004-0637

    Last Modified: 16 Apr 2026

    Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.

    Published: 2 Sept 2004
    7.5
    High

    CVE-2004-0826

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.

    Published: 2 Sept 2004