CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-1078

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element.

    Published: 26 Apr 2004
    5
    Medium

    CVE-2004-1077

    Last Modified: 16 Apr 2026

    Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.

    Published: 26 Apr 2004
    2.1
    Low

    CVE-2004-1355

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.

    Published: 26 Apr 2004
    5
    Medium

    CVE-2004-1968

    Last Modified: 16 Apr 2026

    The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.

    Published: 26 Apr 2004
    7.5
    High

    CVE-2004-1970

    Last Modified: 16 Apr 2026

    Samsung SmartEther SS6215S switch, and possibly other Samsung switches, allows remote attackers and local users to gain administrative access by providing the admin username followed by a password that is the maximum allowed length, then pressing the enter key after the resulting error message.

    Published: 26 Apr 2004
    5
    Medium

    CVE-2004-1971

    Last Modified: 16 Apr 2026

    modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message.

    Published: 26 Apr 2004
    7.5
    High

    CVE-2004-1972

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.

    Published: 26 Apr 2004
    5
    Medium

    CVE-2004-0426

    Last Modified: 16 Apr 2026

    rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.

    Published: 26 Apr 2004
    8.8
    High

    CVE-2004-1967

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary code by including the code in an image tag or a link.

    Published: 25 Apr 2004
    7.5
    High

    CVE-2004-1969

    Last Modified: 16 Apr 2026

    The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript.

    Published: 25 Apr 2004
    4.3
    Medium

    CVE-2004-1965

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.

    Published: 25 Apr 2004
    2.1
    Low

    CVE-2004-1356

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.

    Published: 23 Apr 2004
    7.5
    High

    CVE-2004-1961

    Last Modified: 16 Apr 2026

    blocker.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection protection and execute limited SQL commands via URL-encoded "'" characters ("%27").

    Published: 23 Apr 2004
    5
    Medium

    CVE-2004-1963

    Last Modified: 16 Apr 2026

    nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to obtain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.

    Published: 23 Apr 2004
    4.3
    Medium

    CVE-2004-1964

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in nqt.php in Network Query Tool (NQT) 1.6 allows remote attackers to inject arbitrary web script or HTML via the portNum parameter.

    Published: 23 Apr 2004
    5
    Medium

    CVE-2004-1959

    Last Modified: 16 Apr 2026

    blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.

    Published: 23 Apr 2004
    7.5
    High

    CVE-2004-1952

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.

    Published: 23 Apr 2004
    5
    Medium

    CVE-2004-1956

    Last Modified: 16 Apr 2026

    PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.

    Published: 21 Apr 2004
    2.6
    Low

    CVE-2004-1957

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.

    Published: 21 Apr 2004
    4.3
    Medium

    CVE-2004-1954

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.

    Published: 21 Apr 2004
    5
    Medium

    CVE-2004-1992

    Last Modified: 16 Apr 2026

    Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.

    Published: 20 Apr 2004
    4.6
    Medium

    CVE-2004-1948

    Last Modified: 16 Apr 2026

    NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.

    Published: 20 Apr 2004
    1.2
    Low

    CVE-2004-0404

    Last Modified: 16 Apr 2026

    logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.

    Published: 20 Apr 2004
    10
    Critical

    CVE-2004-0420

    Last Modified: 16 Apr 2026

    The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.

    Published: 20 Apr 2004
    2.1
    Low

    CVE-2004-0423

    Last Modified: 16 Apr 2026

    The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack on the ssmtp.log temporary log file.

    Published: 20 Apr 2004
    7.5
    High

    CVE-2004-1945

    Last Modified: 16 Apr 2026

    Buffer overflow in Kinesphere eXchange POP3 allows remote attackers to execute arbitrary code via a long MAIL FROM field.

    Published: 20 Apr 2004
    7.2
    High

    CVE-2004-0424

    Last Modified: 16 Apr 2026

    Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.

    Published: 20 Apr 2004
    4.6
    Medium

    CVE-2004-1946

    Last Modified: 16 Apr 2026

    Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.

    Published: 19 Apr 2004
    5
    Medium

    CVE-2004-1950

    Last Modified: 16 Apr 2026

    phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.

    Published: 19 Apr 2004
    7.5
    High

    CVE-2004-1938

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is translated to "'", as demonstrated using the phorum_uriauth parameter to list.php.

    Published: 19 Apr 2004
    5
    Medium

    CVE-2004-1947

    Last Modified: 16 Apr 2026

    The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.

    Published: 19 Apr 2004
    5
    Medium

    CVE-2004-1941

    Last Modified: 16 Apr 2026

    Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.

    Published: 19 Apr 2004
    7.5
    High

    CVE-2004-1942

    Last Modified: 16 Apr 2026

    The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map such as passwd.adjunct.byname.

    Published: 19 Apr 2004
    7.5
    High

    CVE-2004-1943

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

    Published: 19 Apr 2004
    2.1
    Low

    CVE-2004-0133

    Last Modified: 16 Apr 2026

    The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.

    Published: 17 Apr 2004
    5
    Medium

    CVE-2004-0156

    Last Modified: 16 Apr 2026

    Format string vulnerabilities in the (1) die or (2) log_event functions for ssmtp before 2.50.6 allow remote mail relays to cause a denial of service and possibly execute arbitrary code.

    Published: 17 Apr 2004
    4.6
    Medium

    CVE-2004-0157

    Last Modified: 16 Apr 2026

    x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.

    Published: 17 Apr 2004
    7.5
    High

    CVE-2004-0389

    Last Modified: 16 Apr 2026

    RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.

    Published: 17 Apr 2004
    2.6
    Low

    CVE-2004-0407

    Last Modified: 16 Apr 2026

    The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.

    Published: 17 Apr 2004
    5
    Medium

    CVE-2003-0663

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.

    Published: 16 Apr 2004
    7.5
    High

    CVE-2004-0119

    Last Modified: 16 Apr 2026

    The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.

    Published: 16 Apr 2004
    7.5
    High

    CVE-2003-0533

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

    Published: 16 Apr 2004
    7.5
    High

    CVE-2003-0719

    Last Modified: 16 Apr 2026

    Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.

    Published: 16 Apr 2004
    7.5
    High

    CVE-2003-0806

    Last Modified: 16 Apr 2026

    Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.

    Published: 16 Apr 2004
    5.1
    Medium

    CVE-2003-0907

    Last Modified: 16 Apr 2026

    Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.

    Published: 16 Apr 2004
    7.2
    High

    CVE-2003-0908

    Last Modified: 16 Apr 2026

    The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.

    Published: 16 Apr 2004
    5
    Medium

    CVE-2004-0116

    Last Modified: 16 Apr 2026

    An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.

    Published: 16 Apr 2004
    7.5
    High

    CVE-2004-0123

    Last Modified: 16 Apr 2026

    Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 16 Apr 2004
    10
    Critical

    CVE-2004-0391

    Last Modified: 16 Apr 2026

    Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.

    Published: 16 Apr 2004
    5
    Medium

    CVE-2002-0385

    Last Modified: 16 Apr 2026

    Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL interpreter to crash and include stack data in the output.

    Published: 16 Apr 2004