CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2004-2031

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in user.php in e107 allows remote attackers to inject arbitrary web script or HTML via the (1) URL, (2) MSN, or (3) AIM fields.

    Published: 21 May 2004
    7.5
    High

    CVE-2003-1041

    Last Modified: 16 Apr 2026

    Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension. NOTE: this bug may overlap CVE-2004-0475.

    Published: 20 May 2004
    Unknown

    CVE-2004-0472

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is a reservation duplicate of CVE-2004-0434. Notes: All CVE users should reference CVE-2004-0434 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 May 2004
    5
    Medium

    CVE-2004-0483

    Last Modified: 16 Apr 2026

    Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests.

    Published: 20 May 2004
    2.6
    Low

    CVE-2004-0484

    Last Modified: 16 Apr 2026

    mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.

    Published: 20 May 2004
    7.5
    High

    CVE-2002-1580

    Last Modified: 16 Apr 2026

    Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.

    Published: 20 May 2004
    10
    Critical

    CVE-2004-0444

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte in the first-level decoding routine for NetBIOS Name Service (NBNS) that modifies an index variable and leads to a stack-based buffer overflow, (2) a heap-based corruption problem in an NBNS response that is missing certain RR fields, and (3) a stack-based buffer overflow in the DNS component via a Resource Record (RR) with a long canonical name (CNAME) field composed of many smaller components.

    Published: 20 May 2004
    2.6
    Low

    CVE-2004-0445

    Last Modified: 16 Apr 2026

    The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.

    Published: 20 May 2004
    5
    Medium

    CVE-2004-0459

    Last Modified: 16 Apr 2026

    The Clear Channel Assessment (CCA) algorithm in the IEEE 802.11 wireless protocol, when using DSSS transmission encoding, allows remote attackers to cause a denial of service via a certain RF signal that causes a channel to appear busy (aka "jabber"), which prevents devices from transmitting data.

    Published: 20 May 2004
    2.1
    Low

    CVE-2004-0471

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for starting and stopping servers for users in the Admin and Operator security roles, which allows unauthorized users to cause a denial of service (service shutdown).

    Published: 20 May 2004
    5.1
    Medium

    CVE-2004-0474

    Last Modified: 16 Apr 2026

    Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL. NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.

    Published: 20 May 2004
    5.1
    Medium

    CVE-2004-0475

    Last Modified: 16 Apr 2026

    The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm. NOTE: this bug may overlap CVE-2003-1041.

    Published: 20 May 2004
    7.5
    High

    CVE-2004-0470

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2, when editing weblogic.xml using WebLogic Builder or the SecurityRoleAssignmentMBean.toXML method, inadvertently removes security-role-assignment tags when weblogic.xml does not have a principal-name tag, which can remove intended access restrictions for the associated web application.

    Published: 20 May 2004
    2.6
    Low

    CVE-2004-0473

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a telnet URI, which allows remote attackers to insert options to the resulting command line and overwrite arbitrary files via (1) the "-f" option on Windows XP or (2) the "-n" option on Linux.

    Published: 20 May 2004
    2.6
    Low

    CVE-2004-0478

    Last Modified: 16 Apr 2026

    Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop that continues to add input to a form, possibly as the result of inserting control characters, as demonstrated using an embedded ctrl-U.

    Published: 20 May 2004
    5
    Medium

    CVE-2004-0479

    Last Modified: 16 Apr 2026

    Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which triggers a null dereference.

    Published: 20 May 2004
    4.6
    Medium

    CVE-2004-0482

    Last Modified: 16 Apr 2026

    Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow local users to read sensitive kernel memory and possibly perform other unauthorized activities.

    Published: 20 May 2004
    7.5
    High

    CVE-2004-0398

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.

    Published: 19 May 2004
    7.5
    High

    CVE-2004-0396

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.

    Published: 19 May 2004
    7.5
    High

    CVE-2004-0419

    Last Modified: 16 Apr 2026

    XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.

    Published: 19 May 2004
    7.5
    High

    CVE-2004-0488

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.

    Published: 17 May 2004
    7.5
    High

    CVE-2004-0411

    Last Modified: 16 Apr 2026

    The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.

    Published: 17 May 2004
    2.6
    Low

    CVE-2004-2014

    Last Modified: 16 Apr 2026

    Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.

    Published: 16 May 2004
    10
    Critical

    CVE-2004-0769

    Last Modified: 16 Apr 2026

    Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than CVE-2004-0771.

    Published: 15 May 2004
    10
    Critical

    CVE-2004-0771

    Last Modified: 16 Apr 2026

    Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.

    Published: 15 May 2004
    5.1
    Medium

    CVE-2004-0199

    Last Modified: 16 Apr 2026

    Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).

    Published: 14 May 2004
    10
    Critical

    CVE-2004-0469

    Last Modified: 16 Apr 2026

    Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemote/SecureClient R56, may allow remote attackers to execute arbitrary code during VPN tunnel negotiation.

    Published: 14 May 2004
    5
    Medium

    CVE-2004-1354

    Last Modified: 16 Apr 2026

    The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.

    Published: 14 May 2004
    10
    Critical

    CVE-2004-0401

    Last Modified: 16 Apr 2026

    Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.

    Published: 14 May 2004
    2.1
    Low

    CVE-2004-0535

    Last Modified: 16 Apr 2026

    The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.

    Published: 14 May 2004
    5
    Medium

    CVE-2004-0506

    Last Modified: 16 Apr 2026

    The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.

    Published: 13 May 2004
    10
    Critical

    CVE-2004-0507

    Last Modified: 16 Apr 2026

    Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 13 May 2004
    5
    Medium

    CVE-2004-0505

    Last Modified: 16 Apr 2026

    The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.

    Published: 13 May 2004
    7.5
    High

    CVE-2004-0400

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.

    Published: 12 May 2004
    7.5
    High

    CVE-2004-0399

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.

    Published: 12 May 2004
    9.8
    Critical

    CVE-2004-0434

    Last Modified: 16 Apr 2026

    k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing length is less than 2, which leads to a heap-based buffer overflow.

    Published: 12 May 2004
    7.5
    High

    CVE-2004-0227

    Last Modified: 16 Apr 2026

    Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long query string.

    Published: 12 May 2004
    5.4
    Medium

    CVE-2004-2655

    Last Modified: 16 Apr 2026

    rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms, does not release the keyboard focus when xscreensaver starts, which causes the password to be entered into the active window when the user unlocks the screen.

    Published: 12 May 2004
    5
    Medium

    CVE-2004-2027

    Last Modified: 16 Apr 2026

    Buffer overflow in Icecast 2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a long Basic Authorization header that triggers an out-of-bounds read.

    Published: 10 May 2004
    5.1
    Medium

    CVE-2006-2480

    Last Modified: 16 Apr 2026

    Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

    Published: 10 May 2004
    5
    Medium

    CVE-2004-2009

    Last Modified: 16 Apr 2026

    NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.

    Published: 8 May 2004
    4.6
    Medium

    CVE-2004-2008

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.

    Published: 8 May 2004
    4.3
    Medium

    CVE-2004-2007

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.

    Published: 8 May 2004
    4.6
    Medium

    CVE-2004-2006

    Last Modified: 16 Apr 2026

    Trend Micro OfficeScan 3.0 - 6.0 has default permissions of "Everyone Full Control" on the installation directory and registry keys, which allows local users to disable virus protection.

    Published: 7 May 2004
    7.5
    High

    CVE-2004-2003

    Last Modified: 16 Apr 2026

    Buffer overflow in the ssl_prcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.

    Published: 6 May 2004
    5
    Medium

    CVE-2004-0392

    Last Modified: 16 Apr 2026

    racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields.

    Published: 6 May 2004
    5
    Medium

    CVE-2004-0050

    Last Modified: 16 Apr 2026

    Verity Ultraseek before 5.2.2 allows remote attackers to obtain the full pathname of the document root via an MS-DOS device name in the web search option, such as (1) NUL, (2) CON, (3) AUX, (4) COM1, (5) COM2, and others.

    Published: 6 May 2004
    5.1
    Medium

    CVE-2004-2005

    Last Modified: 16 Apr 2026

    Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.

    Published: 6 May 2004
    10
    Critical

    CVE-2004-2004

    Last Modified: 16 Apr 2026

    The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.

    Published: 6 May 2004
    5.1
    Medium

    CVE-2004-0430

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.

    Published: 6 May 2004