CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-0754

    Last Modified: 16 Apr 2026

    Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.

    Published: 26 Aug 2004
    7.5
    High

    CVE-2004-0784

    Last Modified: 16 Apr 2026

    The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.

    Published: 26 Aug 2004
    5
    Medium

    CVE-2004-0819

    Last Modified: 16 Apr 2026

    The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service (crash) via an ICMP echo (ping) packet.

    Published: 25 Aug 2004
    5
    Medium

    CVE-2004-1662

    Last Modified: 16 Apr 2026

    YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.

    Published: 25 Aug 2004
    7.5
    High

    CVE-2004-0817

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.

    Published: 25 Aug 2004
    7.5
    High

    CVE-2004-1752

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header.

    Published: 24 Aug 2004
    5
    Medium

    CVE-2004-1742

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.

    Published: 24 Aug 2004
    4.6
    Medium

    CVE-2004-0800

    Last Modified: 16 Apr 2026

    Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.

    Published: 24 Aug 2004
    5
    Medium

    CVE-2004-1744

    Last Modified: 16 Apr 2026

    Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests.

    Published: 24 Aug 2004
    5
    Medium

    CVE-2004-1745

    Last Modified: 16 Apr 2026

    Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.

    Published: 24 Aug 2004
    5
    Medium

    CVE-2004-1743

    Last Modified: 16 Apr 2026

    Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to view arbitrary files via an HTTP request for the disk_c virtual folder.

    Published: 24 Aug 2004
    7.5
    High

    CVE-2004-0827

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.

    Published: 24 Aug 2004
    5
    Medium

    CVE-2004-1741

    Last Modified: 16 Apr 2026

    Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument, then calling SHOWLIST.

    Published: 23 Aug 2004
    5
    Medium

    CVE-2004-1740

    Last Modified: 16 Apr 2026

    Music daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling SHOWLIST.

    Published: 23 Aug 2004
    5
    Medium

    CVE-2004-1739

    Last Modified: 16 Apr 2026

    Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.

    Published: 23 Aug 2004
    1.2
    Low

    CVE-2004-1058

    Last Modified: 16 Apr 2026

    Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.

    Published: 23 Aug 2004
    4.3
    Medium

    CVE-2004-1735

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.

    Published: 21 Aug 2004
    5
    Medium

    CVE-2004-0558

    Last Modified: 16 Apr 2026

    The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.

    Published: 21 Aug 2004
    5
    Medium

    CVE-2004-1733

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in MyDMS 1.4.2 and other versions allows remote registered users to read arbitrary files via .. (dot dot) sequences in the URL.

    Published: 20 Aug 2004
    7.2
    High

    CVE-2004-0795

    Last Modified: 16 Apr 2026

    DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.

    Published: 20 Aug 2004
    7.2
    High

    CVE-2002-1583

    Last Modified: 16 Apr 2026

    Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.

    Published: 20 Aug 2004
    7.2
    High

    CVE-2003-1052

    Last Modified: 16 Apr 2026

    IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.

    Published: 20 Aug 2004
    5
    Medium

    CVE-2004-1727

    Last Modified: 16 Apr 2026

    BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.

    Published: 20 Aug 2004
    7.5
    High

    CVE-2004-1728

    Last Modified: 16 Apr 2026

    Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a long string.

    Published: 20 Aug 2004
    4.3
    Medium

    CVE-2004-1729

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

    Published: 20 Aug 2004
    5
    Medium

    CVE-2004-1731

    Last Modified: 16 Apr 2026

    signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.

    Published: 20 Aug 2004
    7.5
    High

    CVE-2004-1732

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in out.ViewFolder.php in MyDMS before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the folderid parameter.

    Published: 20 Aug 2004
    7.5
    High

    CVE-2004-1726

    Last Modified: 16 Apr 2026

    Multiple integer overflows in (1) xviris.c, (2) xvpcx.c, and (3) xvpm.c in XV allow remote attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.

    Published: 20 Aug 2004
    4.6
    Medium

    CVE-2003-1049

    Last Modified: 16 Apr 2026

    IBM DB2 Universal Database 7 before FixPak 12 creates certain DMS directories with insecure permissions (777), which allows local users to modify or delete certain DB2 files.

    Published: 20 Aug 2004
    7.2
    High

    CVE-2003-1050

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via long command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.

    Published: 20 Aug 2004
    7.2
    High

    CVE-2003-1051

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in IBM DB2 Universal Database 8.1 may allow local users to execute arbitrary code via certain command line arguments to (1) db2start, (2) db2stop, or (3) db2govd.

    Published: 20 Aug 2004
    7.5
    High

    CVE-2004-0746

    Last Modified: 16 Apr 2026

    Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

    Published: 20 Aug 2004
    5
    Medium

    CVE-2004-0753

    Last Modified: 16 Apr 2026

    The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.

    Published: 20 Aug 2004
    5.1
    Medium

    CVE-2004-0794

    Last Modified: 16 Apr 2026

    Multiple signal handler race conditions in lukemftpd (aka tnftpd before 20040810) allow remote authenticated attackers to cause a denial of service or execute arbitrary code.

    Published: 19 Aug 2004
    7.5
    High

    CVE-2004-0408

    Last Modified: 16 Apr 2026

    Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.

    Published: 19 Aug 2004
    7.5
    High

    CVE-2004-0458

    Last Modified: 16 Apr 2026

    mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer dereference.

    Published: 19 Aug 2004
    7.5
    High

    CVE-2004-0768

    Last Modified: 16 Apr 2026

    libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.

    Published: 19 Aug 2004
    7.5
    High

    CVE-2004-0777

    Last Modified: 16 Apr 2026

    Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.

    Published: 19 Aug 2004
    7.5
    High

    CVE-2004-1724

    Last Modified: 16 Apr 2026

    The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.

    Published: 18 Aug 2004
    5
    Medium

    CVE-2003-0105

    Last Modified: 16 Apr 2026

    ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.

    Published: 18 Aug 2004
    7.5
    High

    CVE-2004-0593

    Last Modified: 16 Apr 2026

    Sygate Enforcer 3.5MR1 and earlier passes broadcast traffic before authentication, which could allow remote attackers to bypass filtering rules.

    Published: 18 Aug 2004
    5
    Medium

    CVE-2004-0839

    Last Modified: 16 Apr 2026

    Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

    Published: 18 Aug 2004
    7.5
    High

    CVE-2003-0928

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.

    Published: 18 Aug 2004
    7.5
    High

    CVE-2003-0929

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.

    Published: 18 Aug 2004
    7.5
    High

    CVE-2003-0930

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.

    Published: 18 Aug 2004
    5
    Medium

    CVE-2003-0931

    Last Modified: 16 Apr 2026

    Sygate Enforcer 4.0 earlier allows remote attackers to cause a denial of service (service hang) by replaying a malformed discovery packet to UDP port 39999.

    Published: 18 Aug 2004
    5
    Medium

    CVE-2004-0163

    Last Modified: 16 Apr 2026

    Sygate Secure Enterprise (SSE) 3.5MR3 and earlier does not change the key used to encrypt data, which allows remote attackers to cause a denial of service (resource exhaustion) by capturing a session and repeatedly replaying the session.

    Published: 18 Aug 2004
    7.5
    High

    CVE-2004-0629

    Last Modified: 16 Apr 2026

    Buffer overflow in the ActiveX component (pdf.ocx) for Adobe Acrobat 5.0.5 and Acrobat Reader, and possibly other versions, allows remote attackers to execute arbitrary code via a URI for a PDF file with a null terminator (%00) followed by a long string.

    Published: 18 Aug 2004
    5
    Medium

    CVE-2004-0693

    Last Modified: 16 Apr 2026

    The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0692.

    Published: 18 Aug 2004
    5
    Medium

    CVE-2004-0692

    Last Modified: 16 Apr 2026

    The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null dereference, a different vulnerability than CVE-2004-0693.

    Published: 18 Aug 2004