CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2004-0633

    Last Modified: 16 Apr 2026

    The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.

    Published: 6 Jul 2004
    5
    Medium

    CVE-2004-0635

    Last Modified: 16 Apr 2026

    The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.

    Published: 6 Jul 2004
    5
    Medium

    CVE-2004-0634

    Last Modified: 16 Apr 2026

    The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.

    Published: 6 Jul 2004
    10
    Critical

    CVE-2004-0627

    Last Modified: 16 Apr 2026

    The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.

    Published: 5 Jul 2004
    10
    Critical

    CVE-2004-0628

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.

    Published: 5 Jul 2004
    5
    Medium

    CVE-2004-0758

    Last Modified: 16 Apr 2026

    Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.

    Published: 3 Jul 2004
    7.5
    High

    CVE-2004-0721

    Last Modified: 16 Apr 2026

    Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

    Published: 1 Jul 2004
    5
    Medium

    CVE-2004-0762

    Last Modified: 16 Apr 2026

    Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

    Published: 1 Jul 2004
    7.5
    High

    CVE-2004-0718

    Last Modified: 16 Apr 2026

    The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

    Published: 1 Jul 2004
    7.2
    High

    CVE-2004-0454

    Last Modified: 16 Apr 2026

    Buffer overflow in the msg function for rlpr daemon (rlprd) 2.04 allows local users to execute arbitrary code.

    Published: 30 Jun 2004
    6.8
    Medium

    CVE-2004-0606

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Infoblox DNS One running firmware 2.4.0-8 and earlier allows remote attackers to execute arbitrary scripts as other users via the (1) CLIENTID or (2) HOSTNAME option of a DHCP request.

    Published: 30 Jun 2004
    2.1
    Low

    CVE-2004-0622

    Last Modified: 16 Apr 2026

    Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.

    Published: 30 Jun 2004
    10
    Critical

    CVE-2004-0608

    Last Modified: 16 Apr 2026

    The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.

    Published: 30 Jun 2004
    5
    Medium

    CVE-2004-0610

    Last Modified: 16 Apr 2026

    The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.

    Published: 30 Jun 2004
    5.1
    Medium

    CVE-2004-0612

    Last Modified: 16 Apr 2026

    The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filtering. NOTE: it has been disputed by the vendor that this behavior is required by the SSL specification.

    Published: 30 Jun 2004
    7.5
    High

    CVE-2004-0613

    Last Modified: 16 Apr 2026

    osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.

    Published: 30 Jun 2004
    6.4
    Medium

    CVE-2004-0614

    Last Modified: 16 Apr 2026

    osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.

    Published: 30 Jun 2004
    5
    Medium

    CVE-2004-0616

    Last Modified: 16 Apr 2026

    The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext.

    Published: 30 Jun 2004
    10
    Critical

    CVE-2004-0623

    Last Modified: 16 Apr 2026

    Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

    Published: 30 Jun 2004
    7.5
    High

    CVE-2004-0624

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php for Artmedic links 5.0 (artmedic_links5) allows remote attackers to execute arbitrary PHP code by modifying the id parameter to reference a URL on a remote web server that contains the code.

    Published: 30 Jun 2004
    10
    Critical

    CVE-2004-0451

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog.

    Published: 30 Jun 2004
    7.2
    High

    CVE-2004-0455

    Last Modified: 16 Apr 2026

    Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.

    Published: 30 Jun 2004
    10
    Critical

    CVE-2004-0480

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.

    Published: 30 Jun 2004
    5
    Medium

    CVE-2004-0576

    Last Modified: 16 Apr 2026

    The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing an invalid OID.

    Published: 30 Jun 2004
    10
    Critical

    CVE-2004-0603

    Last Modified: 16 Apr 2026

    gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.

    Published: 30 Jun 2004
    5
    Medium

    CVE-2004-0604

    Last Modified: 16 Apr 2026

    The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.

    Published: 30 Jun 2004
    5
    Medium

    CVE-2004-0609

    Last Modified: 16 Apr 2026

    rssh 2.0 through 2.1.x expands command line arguments before entering a chroot jail, which allows remote authenticated users to determine the existence of files in a directory outside the jail.

    Published: 30 Jun 2004
    5
    Medium

    CVE-2004-0611

    Last Modified: 16 Apr 2026

    Web-Based Administration in Netgear FVS318 VPN Router allows remote attackers to cause a denial of service (no new connections) via a large number of open HTTP connections.

    Published: 30 Jun 2004
    6.8
    Medium

    CVE-2004-0617

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.

    Published: 30 Jun 2004
    2.1
    Low

    CVE-2004-0618

    Last Modified: 16 Apr 2026

    FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.

    Published: 30 Jun 2004
    4.3
    Medium

    CVE-2004-0620

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.

    Published: 30 Jun 2004
    7.5
    High

    CVE-2004-0625

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Infinity WEB 1.0 allows remote attackers to bypass authentication and gain privileges via the login page.

    Published: 30 Jun 2004
    10
    Critical

    CVE-2004-0393

    Last Modified: 16 Apr 2026

    Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.

    Published: 30 Jun 2004
    10
    Critical

    CVE-2004-0590

    Last Modified: 16 Apr 2026

    FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject.

    Published: 30 Jun 2004
    5
    Medium

    CVE-2004-0605

    Last Modified: 16 Apr 2026

    Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have a rate-limit imposed, which could allow remote attackers to cause a denial of service by repeatedly making requests, which are slowly dequeued.

    Published: 30 Jun 2004
    5.1
    Medium

    CVE-2004-0615

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.

    Published: 30 Jun 2004
    10
    Critical

    CVE-2004-0621

    Last Modified: 16 Apr 2026

    admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.

    Published: 30 Jun 2004
    2.1
    Low

    CVE-2004-0497

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.

    Published: 30 Jun 2004
    6.4
    Medium

    CVE-2004-0493

    Last Modified: 16 Apr 2026

    The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.

    Published: 28 Jun 2004
    10
    Critical

    CVE-2004-0461

    Last Modified: 16 Apr 2026

    The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.

    Published: 24 Jun 2004
    6.8
    Medium

    CVE-2004-0591

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.

    Published: 24 Jun 2004
    7.2
    High

    CVE-2004-0453

    Last Modified: 16 Apr 2026

    Format string vulnerability in the monitor "memory dump" command in VICE 1.6 to 1.14 allows local users to cause a denial of service (emulator crash) and possibly execute arbitrary code via format string specifiers in an output string.

    Published: 24 Jun 2004
    10
    Critical

    CVE-2004-0460

    Last Modified: 16 Apr 2026

    Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.

    Published: 24 Jun 2004
    5
    Medium

    CVE-2004-0582

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Webmin 1.140 allows remote attackers to bypass access control rules and gain read access to configuration information for a module.

    Published: 23 Jun 2004
    2.1
    Low

    CVE-2004-0136

    Last Modified: 16 Apr 2026

    The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a "corrupted binary."

    Published: 23 Jun 2004
    5
    Medium

    CVE-2004-0580

    Last Modified: 16 Apr 2026

    DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.

    Published: 23 Jun 2004
    7.2
    High

    CVE-2004-0125

    Last Modified: 16 Apr 2026

    The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing table.

    Published: 23 Jun 2004
    7.2
    High

    CVE-2004-0135

    Last Modified: 16 Apr 2026

    The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.

    Published: 23 Jun 2004
    2.1
    Low

    CVE-2004-0137

    Last Modified: 16 Apr 2026

    Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of "page invalidation issues."

    Published: 23 Jun 2004
    10
    Critical

    CVE-2004-0413

    Last Modified: 16 Apr 2026

    libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.

    Published: 23 Jun 2004