CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2003-0807

    Last Modified: 16 Apr 2026

    Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.

    Published: 16 Apr 2004
    7.6
    High

    CVE-2003-0906

    Last Modified: 16 Apr 2026

    Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.

    Published: 16 Apr 2004
    7.2
    High

    CVE-2003-0909

    Last Modified: 16 Apr 2026

    Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."

    Published: 16 Apr 2004
    7.2
    High

    CVE-2003-0910

    Last Modified: 16 Apr 2026

    The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.

    Published: 16 Apr 2004
    7.5
    High

    CVE-2004-0117

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

    Published: 16 Apr 2004
    7.2
    High

    CVE-2004-0118

    Last Modified: 16 Apr 2026

    The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.

    Published: 16 Apr 2004
    5
    Medium

    CVE-2004-0120

    Last Modified: 16 Apr 2026

    The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.

    Published: 16 Apr 2004
    2.6
    Low

    CVE-2004-0124

    Last Modified: 16 Apr 2026

    The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."

    Published: 16 Apr 2004
    7.5
    High

    CVE-2004-0197

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.

    Published: 16 Apr 2004
    10
    Critical

    CVE-2004-0385

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities."

    Published: 16 Apr 2004
    5
    Medium

    CVE-2004-2680

    Last Modified: 16 Apr 2026

    mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.

    Published: 16 Apr 2004
    7.5
    High

    CVE-2004-0121

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.

    Published: 15 Apr 2004
    5
    Medium

    CVE-2004-0122

    Last Modified: 16 Apr 2026

    Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.

    Published: 15 Apr 2004
    7.5
    High

    CVE-2004-0150

    Last Modified: 16 Apr 2026

    Buffer overflow in the getaddrinfo function in Python 2.2 before 2.2.2, when IPv6 support is disabled, allows remote attackers to execute arbitrary code via an IPv6 address that is obtained using DNS.

    Published: 15 Apr 2004
    7.5
    High

    CVE-2004-1934

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.

    Published: 15 Apr 2004
    4.3
    Medium

    CVE-2004-1935

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.

    Published: 15 Apr 2004
    5
    Medium

    CVE-2003-0905

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.

    Published: 15 Apr 2004
    5
    Medium

    CVE-2004-0173

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.

    Published: 15 Apr 2004
    4.3
    Medium

    CVE-2004-1939

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key parameter.

    Published: 14 Apr 2004
    5
    Medium

    CVE-2004-1944

    Last Modified: 16 Apr 2026

    Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.

    Published: 14 Apr 2004
    7.5
    High

    CVE-2004-1936

    Last Modified: 16 Apr 2026

    ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.

    Published: 14 Apr 2004
    6.8
    Medium

    CVE-2004-0179

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

    Published: 14 Apr 2004
    4.6
    Medium

    CVE-2004-0109

    Last Modified: 16 Apr 2026

    Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.

    Published: 14 Apr 2004
    5
    Medium

    CVE-2004-0182

    Last Modified: 16 Apr 2026

    Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.

    Published: 14 Apr 2004
    2.6
    Low

    CVE-2004-0180

    Last Modified: 16 Apr 2026

    The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.

    Published: 14 Apr 2004
    2.1
    Low

    CVE-2004-0388

    Last Modified: 16 Apr 2026

    The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.

    Published: 14 Apr 2004
    5
    Medium

    CVE-2004-0405

    Last Modified: 16 Apr 2026

    CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.

    Published: 14 Apr 2004
    5
    Medium

    CVE-2004-1756

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.

    Published: 13 Apr 2004
    4.6
    Medium

    CVE-2004-1758

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

    Published: 13 Apr 2004
    7.5
    High

    CVE-2004-1929

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.

    Published: 13 Apr 2004
    7.5
    High

    CVE-2004-1928

    Last Modified: 16 Apr 2026

    The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.

    Published: 12 Apr 2004
    5
    Medium

    CVE-2004-1060

    Last Modified: 16 Apr 2026

    Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

    Published: 12 Apr 2004
    7.5
    High

    CVE-2004-1925

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php, (6) tiki-user_tasks.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-file_galleries.php, (10) tiki-list_faqs.php, (11) tiki-list_trackers.php, (12) tiki-list_blogs.php, or via the offset parameter in (13) tiki-usermenu.php, (14) tiki-browse_categories.php, (15) tiki-index.php, (16) tiki-user_tasks.php, (17) tiki-list_faqs.php, (18) tiki-list_trackers.php, or (19) tiki-list_blogs.php.

    Published: 12 Apr 2004
    4.3
    Medium

    CVE-2004-1930

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.

    Published: 12 Apr 2004
    7.5
    High

    CVE-2004-1932

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.

    Published: 12 Apr 2004
    2.1
    Low

    CVE-2004-1933

    Last Modified: 16 Apr 2026

    Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized messages.

    Published: 12 Apr 2004
    6.8
    Medium

    CVE-2004-2760

    Last Modified: 16 Apr 2026

    sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection state, a different vulnerability than CVE-2003-0190. NOTE: it could be argued that in most environments, this does not cross privilege boundaries without requiring leverage of a separate vulnerability.

    Published: 12 Apr 2004
    7.5
    High

    CVE-2004-1926

    Last Modified: 16 Apr 2026

    Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation.

    Published: 11 Apr 2004
    5
    Medium

    CVE-2004-1927

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter.

    Published: 11 Apr 2004
    2.6
    Low

    CVE-2004-1922

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.

    Published: 11 Apr 2004
    5
    Medium

    CVE-2004-1923

    Last Modified: 16 Apr 2026

    Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message.

    Published: 11 Apr 2004
    4.3
    Medium

    CVE-2004-1924

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php, (3) flag, priority, flagval, sort_mode, or find parameters to messu-read.php, (4) articleId parameter to tiki-read_article.php, (5) parentId parameter to tiki-browse_categories.php, (6) comments_threshold parameter to tiki-index.php (7) articleId parameter to tiki-print_article.php, (8) galleryId parameter to tiki-list_file_gallery.php, (9) galleryId parameter to tiki-upload_file.php, (10) faqId parameter to tiki-view_faq.php, (11) chartId parameter to tiki-view_chart.php, or (12) surveyId parameter to tiki-survey_stats_survey.php.

    Published: 11 Apr 2004
    7.5
    High

    CVE-2004-1921

    Last Modified: 16 Apr 2026

    X-Micro WLAN 11b Broadband Router 1.6.0.1 has a hardcoded "1502" username and password, which could allow remote attackers to gain access.

    Published: 10 Apr 2004
    7.5
    High

    CVE-2004-1920

    Last Modified: 16 Apr 2026

    X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.

    Published: 10 Apr 2004
    5
    Medium

    CVE-2004-1919

    Last Modified: 16 Apr 2026

    The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings.

    Published: 9 Apr 2004
    5
    Medium

    CVE-2004-1918

    Last Modified: 16 Apr 2026

    RSniff 1.0 allows remote attackers to cause a denial of service (connection exhaustion) via a large number of connections with a command other than AUTHENTICATE, or without any data, which prevents the socket from being closed properly.

    Published: 9 Apr 2004
    7.5
    High

    CVE-2004-1917

    Last Modified: 16 Apr 2026

    Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.

    Published: 8 Apr 2004
    7.5
    High

    CVE-2004-1916

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to parse_all_client_messages function, or (2) long argv command to test_func_func function.

    Published: 8 Apr 2004
    7.5
    High

    CVE-2004-1915

    Last Modified: 16 Apr 2026

    Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.

    Published: 8 Apr 2004
    2.1
    Low

    CVE-2004-1234

    Last Modified: 16 Apr 2026

    load_elf_binary in Linux before 2.4.26 allows local users to cause a denial of service (system crash) via an ELF binary in which the interpreter is NULL.

    Published: 8 Apr 2004