CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2004-0427

    Last Modified: 16 Apr 2026

    The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.

    Published: 8 Apr 2004
    7.2
    High

    CVE-2004-0382

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.

    Published: 7 Apr 2004
    5
    Medium

    CVE-2004-1357

    Last Modified: 16 Apr 2026

    The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.

    Published: 7 Apr 2004
    6.8
    Medium

    CVE-2004-0379

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.

    Published: 7 Apr 2004
    7.2
    High

    CVE-2004-0383

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."

    Published: 7 Apr 2004
    10
    Critical

    CVE-2004-0386

    Last Modified: 16 Apr 2026

    Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.

    Published: 7 Apr 2004
    10
    Critical

    CVE-2003-0648

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.

    Published: 6 Apr 2004
    2.1
    Low

    CVE-2004-0370

    Last Modified: 16 Apr 2026

    The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.

    Published: 6 Apr 2004
    5
    Medium

    CVE-2004-0371

    Last Modified: 16 Apr 2026

    Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a realm to impersonate others in the cross-realm trust path.

    Published: 6 Apr 2004
    10
    Critical

    CVE-2004-0380

    Last Modified: 16 Apr 2026

    The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

    Published: 6 Apr 2004
    7.5
    High

    CVE-2004-0366

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

    Published: 6 Apr 2004
    5
    Medium

    CVE-2004-0376

    Last Modified: 16 Apr 2026

    oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.

    Published: 6 Apr 2004
    10
    Critical

    CVE-2004-0377

    Last Modified: 16 Apr 2026

    Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.

    Published: 6 Apr 2004
    6.4
    Medium

    CVE-2004-0374

    Last Modified: 16 Apr 2026

    Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.

    Published: 6 Apr 2004
    4.6
    Medium

    CVE-2004-1772

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.

    Published: 6 Apr 2004
    5.1
    Medium

    CVE-2004-0387

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file.

    Published: 6 Apr 2004
    5
    Medium

    CVE-2004-2392

    Last Modified: 16 Apr 2026

    libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs.

    Published: 6 Apr 2004
    7.5
    High

    CVE-2004-0155

    Last Modified: 16 Apr 2026

    The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.

    Published: 5 Apr 2004
    7.5
    High

    CVE-2004-0409

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.

    Published: 5 Apr 2004
    5
    Medium

    CVE-2004-1986

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.

    Published: 4 Apr 2004
    2.1
    Low

    CVE-2004-0233

    Last Modified: 16 Apr 2026

    Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

    Published: 3 Apr 2004
    5
    Medium

    CVE-2004-1890

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.

    Published: 2 Apr 2004
    5
    Medium

    CVE-2004-0403

    Last Modified: 16 Apr 2026

    Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.

    Published: 31 Mar 2004
    2.6
    Low

    CVE-2004-1877

    Last Modified: 16 Apr 2026

    The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.

    Published: 30 Mar 2004
    9.3
    Critical

    CVE-2004-1875

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter to ignorelist.html, (5) account parameter to showlog.html, (6) db parameter to repairdb.html, (7) login parameter to doaddftp.html (8) account parameter to editmsg.htm, or (9) ip parameter to del.html. NOTE: the dnslook.html vector was later reported to exist in cPanel 10.

    Published: 30 Mar 2004
    4.6
    Medium

    CVE-2004-1876

    Last Modified: 16 Apr 2026

    The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.

    Published: 30 Mar 2004
    5
    Medium

    CVE-2004-1878

    Last Modified: 16 Apr 2026

    LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash).

    Published: 30 Mar 2004
    7.2
    High

    CVE-2004-0160

    Last Modified: 16 Apr 2026

    Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.

    Published: 29 Mar 2004
    7.5
    High

    CVE-2004-1870

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.

    Published: 29 Mar 2004
    4.3
    Medium

    CVE-2004-1874

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HTML via the user information forms.

    Published: 29 Mar 2004
    4.3
    Medium

    CVE-2004-1872

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style tag.

    Published: 29 Mar 2004
    4.3
    Medium

    CVE-2004-1871

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.

    Published: 29 Mar 2004
    7.5
    High

    CVE-2003-0993

    Last Modified: 16 Apr 2026

    mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.

    Published: 29 Mar 2004
    4.6
    Medium

    CVE-2004-0126

    Last Modified: 16 Apr 2026

    The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail.

    Published: 29 Mar 2004
    7.5
    High

    CVE-2004-0194

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.

    Published: 29 Mar 2004
    5
    Medium

    CVE-2004-0183

    Last Modified: 16 Apr 2026

    TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

    Published: 29 Mar 2004
    5
    Medium

    CVE-2004-0184

    Last Modified: 16 Apr 2026

    Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

    Published: 29 Mar 2004
    7.5
    High

    CVE-2004-0152

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachments with filenames.

    Published: 27 Mar 2004
    7.5
    High

    CVE-2004-0153

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.

    Published: 27 Mar 2004
    2.1
    Low

    CVE-2004-0372

    Last Modified: 16 Apr 2026

    xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.

    Published: 27 Mar 2004
    4.3
    Medium

    CVE-2004-1862

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest parameter to stats.php, (4) message or icons parameter to post.php, (5) threadlist, pagelinks, forumlist, navigation, or (6) forumdisplay parameter to forumdisplay.php.

    Published: 26 Mar 2004
    4.8
    Medium

    CVE-2004-1865

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname). NOTE: if administrators are normally allowed to add HTML by other means, e.g. through Smarty templates, then this issue would not give any additional privileges, and thus would not be considered a vulnerability.

    Published: 26 Mar 2004
    7.5
    High

    CVE-2004-1864

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php.

    Published: 26 Mar 2004
    5
    Medium

    CVE-2004-1866

    Last Modified: 16 Apr 2026

    nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.

    Published: 26 Mar 2004
    2.1
    Low

    CVE-2004-0178

    Last Modified: 16 Apr 2026

    The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not properly handle certain sample sizes, which allows local users to cause a denial of service (crash) via a sample with an odd number of bytes.

    Published: 26 Mar 2004
    4.6
    Medium

    CVE-2004-0149

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.

    Published: 25 Mar 2004
    10
    Critical

    CVE-2004-0220

    Last Modified: 16 Apr 2026

    isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demonstrated by the Striker ISAKMP Protocol Test Suite.

    Published: 25 Mar 2004
    5
    Medium

    CVE-2004-0221

    Last Modified: 16 Apr 2026

    isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-bounds read error, as demonstrated by the Striker ISAKMP Protocol Test Suite.

    Published: 25 Mar 2004
    5
    Medium

    CVE-2004-0222

    Last Modified: 16 Apr 2026

    Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Protocol Test Suite.

    Published: 25 Mar 2004
    4.6
    Medium

    CVE-2004-1861

    Last Modified: 16 Apr 2026

    Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.

    Published: 25 Mar 2004