CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2004-1658

    Last Modified: 16 Apr 2026

    Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physicalmemory to restore the running kernel's SDT ServiceTable.

    Published: 2 Sept 2004
    4.3
    Medium

    CVE-2004-1659

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.

    Published: 2 Sept 2004
    7.5
    High

    CVE-2004-1661

    Last Modified: 16 Apr 2026

    MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."

    Published: 2 Sept 2004
    5
    Medium

    CVE-2004-0306

    Last Modified: 16 Apr 2026

    Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port 69 by default, which allows remote attackers to GET or PUT ONS system files on the current active TCC in the /flash0 or /flash1 directories.

    Published: 1 Sept 2004
    9.3
    Critical

    CVE-2004-0273

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.

    Published: 1 Sept 2004
    7.5
    High

    CVE-2004-0274

    Last Modified: 16 Apr 2026

    Share.mod in Eggheads Eggdrop IRC bot 1.6.10 through 1.6.15 can mistakenly assign STAT_OFFERED status to a bot that is not a sharebot, which allows remote attackers to use STAT_OFFERED to promote a bot to a sharebot and conduct unauthorized activities.

    Published: 1 Sept 2004
    10
    Critical

    CVE-2004-0297

    Last Modified: 16 Apr 2026

    Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.

    Published: 1 Sept 2004
    7.2
    High

    CVE-2004-1372

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the generate_distfile procedure.

    Published: 1 Sept 2004
    5
    Medium

    CVE-2004-0270

    Last Modified: 16 Apr 2026

    libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.

    Published: 1 Sept 2004
    5
    Medium

    CVE-2004-0307

    Last Modified: 16 Apr 2026

    Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) by not sending the ACK portion of the TCP three-way handshake and sending an invalid response instead.

    Published: 1 Sept 2004
    5
    Medium

    CVE-2004-0336

    Last Modified: 16 Apr 2026

    LAN SUITE Web Mail 602Pro allows remote attackers to gain sensitive information via the mail login form, which contains the path to the mail directory.

    Published: 1 Sept 2004
    4.3
    Medium

    CVE-2004-1655

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.

    Published: 1 Sept 2004
    5
    Medium

    CVE-2004-1656

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.

    Published: 1 Sept 2004
    4.3
    Medium

    CVE-2004-1657

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.

    Published: 1 Sept 2004
    7.5
    High

    CVE-2004-1654

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the calendar module in phpWebsite 0.9.3-4 and earlier allows remote attackers to execute arbitrary SQL commands via cal_template.

    Published: 1 Sept 2004
    10
    Critical

    CVE-2004-0261

    Last Modified: 16 Apr 2026

    oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.

    Published: 1 Sept 2004
    5
    Medium

    CVE-2004-0263

    Last Modified: 16 Apr 2026

    PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.

    Published: 1 Sept 2004
    5
    Medium

    CVE-2004-0276

    Last Modified: 16 Apr 2026

    The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.

    Published: 1 Sept 2004
    10
    Critical

    CVE-2004-0309

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5.085, allows remote attackers to execute arbitrary code via a long RCPT TO argument.

    Published: 1 Sept 2004
    2.1
    Low

    CVE-2004-0320

    Last Modified: 16 Apr 2026

    Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequences of commands.

    Published: 1 Sept 2004
    6
    Medium

    CVE-2004-0347

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter.

    Published: 1 Sept 2004
    10
    Critical

    CVE-2004-0356

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Supervisor Report Center in SL Mail Pro 2.0.9 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a long HTTP sub-version.

    Published: 1 Sept 2004
    2.1
    Low

    CVE-2004-0256

    Last Modified: 16 Apr 2026

    GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.

    Published: 1 Sept 2004
    5
    Medium

    CVE-2004-0257

    Last Modified: 16 Apr 2026

    OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.

    Published: 1 Sept 2004
    7.5
    High

    CVE-2004-1650

    Last Modified: 16 Apr 2026

    D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.

    Published: 31 Aug 2004
    4.3
    Medium

    CVE-2004-1648

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.

    Published: 31 Aug 2004
    7.2
    High

    CVE-2004-1774

    Last Modified: 16 Apr 2026

    Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.

    Published: 31 Aug 2004
    6.4
    Medium

    CVE-2004-1653

    Last Modified: 16 Apr 2026

    The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.

    Published: 31 Aug 2004
    7.2
    High

    CVE-2004-1649

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future.

    Published: 31 Aug 2004
    4.3
    Medium

    CVE-2004-1651

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.

    Published: 31 Aug 2004
    7.5
    High

    CVE-2004-1652

    Last Modified: 16 Apr 2026

    phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.

    Published: 31 Aug 2004
    7.5
    High

    CVE-2004-0642

    Last Modified: 16 Apr 2026

    Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.

    Published: 31 Aug 2004
    4.6
    Medium

    CVE-2004-0643

    Last Modified: 16 Apr 2026

    Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.

    Published: 31 Aug 2004
    5
    Medium

    CVE-2004-0644

    Last Modified: 16 Apr 2026

    The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.

    Published: 31 Aug 2004
    4
    Medium

    CVE-2004-0908

    Last Modified: 16 Apr 2026

    Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows untrusted Javascript code to read and write to the clipboard, and possibly obtain sensitive information, via script-generated events such as Ctrl-Ins.

    Published: 31 Aug 2004
    7.5
    High

    CVE-2004-1660

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.

    Published: 30 Aug 2004
    7.5
    High

    CVE-2004-1647

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.

    Published: 30 Aug 2004
    5
    Medium

    CVE-2004-1646

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 30 Aug 2004
    4.3
    Medium

    CVE-2004-1645

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.

    Published: 30 Aug 2004
    5
    Medium

    CVE-2004-1644

    Last Modified: 16 Apr 2026

    Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address.

    Published: 30 Aug 2004
    5
    Medium

    CVE-2004-1641

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.

    Published: 29 Aug 2004
    5
    Medium

    CVE-2004-1642

    Last Modified: 16 Apr 2026

    WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.

    Published: 29 Aug 2004
    5
    Medium

    CVE-2004-1643

    Last Modified: 16 Apr 2026

    WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.

    Published: 29 Aug 2004
    10
    Critical

    CVE-2004-0903

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.

    Published: 29 Aug 2004
    4.6
    Medium

    CVE-2004-0820

    Last Modified: 16 Apr 2026

    Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.

    Published: 28 Aug 2004
    4.3
    Medium

    CVE-2004-1640

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.

    Published: 28 Aug 2004
    7.5
    High

    CVE-2004-0798

    Last Modified: 16 Apr 2026

    Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.

    Published: 27 Aug 2004
    10
    Critical

    CVE-2004-0904

    Last Modified: 16 Apr 2026

    Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.

    Published: 27 Aug 2004
    5
    Medium

    CVE-2004-1751

    Last Modified: 16 Apr 2026

    Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet, which generates a "Message too long" socket error that is treated as a critical error.

    Published: 26 Aug 2004
    7.2
    High

    CVE-2004-1681

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.

    Published: 26 Aug 2004