CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2003-0781

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.

    Published: 25 Mar 2004
    10
    Critical

    CVE-2003-0782

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 25 Mar 2004
    5
    Medium

    CVE-2004-0218

    Last Modified: 16 Apr 2026

    isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.

    Published: 25 Mar 2004
    10
    Critical

    CVE-2004-0368

    Last Modified: 16 Apr 2026

    Double free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.

    Published: 25 Mar 2004
    5
    Medium

    CVE-2004-0219

    Last Modified: 16 Apr 2026

    isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.

    Published: 25 Mar 2004
    7.5
    High

    CVE-2004-1868

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.

    Published: 25 Mar 2004
    5
    Medium

    CVE-2004-2259

    Last Modified: 16 Apr 2026

    vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant.

    Published: 25 Mar 2004
    5
    Medium

    CVE-2004-1859

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 24 Mar 2004
    7.5
    High

    CVE-2004-2037

    Last Modified: 16 Apr 2026

    Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client.

    Published: 24 Mar 2004
    7.5
    High

    CVE-2004-1851

    Last Modified: 16 Apr 2026

    Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via brute force guessing.

    Published: 24 Mar 2004
    7.5
    High

    CVE-2004-1854

    Last Modified: 16 Apr 2026

    Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.

    Published: 24 Mar 2004
    5
    Medium

    CVE-2004-1856

    Last Modified: 16 Apr 2026

    devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.

    Published: 24 Mar 2004
    2.1
    Low

    CVE-2004-1857

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.

    Published: 24 Mar 2004
    4.3
    Medium

    CVE-2004-1849

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html or (2) handle parameter to addhandle.html.

    Published: 24 Mar 2004
    2.1
    Low

    CVE-2004-0381

    Last Modified: 16 Apr 2026

    mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.

    Published: 24 Mar 2004
    5
    Medium

    CVE-2004-1850

    Last Modified: 16 Apr 2026

    The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero.

    Published: 23 Mar 2004
    7.5
    High

    CVE-2004-0362

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

    Published: 23 Mar 2004
    Unknown

    CVE-2004-1886

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-1848. Reason: This candidate is a duplicate of CVE-2004-1848. Notes: All CVE users should reference CVE-2004-1848 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Mar 2004
    7.5
    High

    CVE-2004-1884

    Last Modified: 16 Apr 2026

    Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.

    Published: 23 Mar 2004
    7.2
    High

    CVE-2004-0151

    Last Modified: 16 Apr 2026

    Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands.

    Published: 23 Mar 2004
    7.5
    High

    CVE-2004-0363

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.

    Published: 23 Mar 2004
    5
    Medium

    CVE-2004-1852

    Last Modified: 16 Apr 2026

    DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.

    Published: 23 Mar 2004
    5
    Medium

    CVE-2004-1855

    Last Modified: 16 Apr 2026

    Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attack.

    Published: 23 Mar 2004
    7.5
    High

    CVE-2004-0364

    Last Modified: 16 Apr 2026

    The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method.

    Published: 23 Mar 2004
    7.5
    High

    CVE-2004-0835

    Last Modified: 16 Apr 2026

    MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.

    Published: 23 Mar 2004
    5
    Medium

    CVE-2004-1838

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in xweb 1.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the URL.

    Published: 22 Mar 2004
    5
    Medium

    CVE-2004-1839

    Last Modified: 16 Apr 2026

    MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.

    Published: 22 Mar 2004
    4.3
    Medium

    CVE-2004-1840

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.

    Published: 22 Mar 2004
    5
    Medium

    CVE-2004-1761

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file.

    Published: 22 Mar 2004
    5
    Medium

    CVE-2004-0367

    Last Modified: 16 Apr 2026

    Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.

    Published: 22 Mar 2004
    7.5
    High

    CVE-2004-1843

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp.

    Published: 20 Mar 2004
    7.5
    High

    CVE-2004-1846

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.

    Published: 20 Mar 2004
    7.5
    High

    CVE-2004-1847

    Last Modified: 16 Apr 2026

    News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.

    Published: 20 Mar 2004
    7.5
    High

    CVE-2004-1833

    Last Modified: 16 Apr 2026

    The admin.ib file in Borland Interbase 7.1 for Linux has default world writable permissions, which allows local users to gain database administrative privileges.

    Published: 20 Mar 2004
    2.1
    Low

    CVE-2004-1834

    Last Modified: 16 Apr 2026

    mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.

    Published: 20 Mar 2004
    5
    Medium

    CVE-2004-1853

    Last Modified: 16 Apr 2026

    Buffer overflow in Terminator 3: War of the Machines 1.0 allows remote attackers to cause a denial of service via a long ServerInfo variable.

    Published: 19 Mar 2004
    7.5
    High

    CVE-2004-0174

    Last Modified: 16 Apr 2026

    Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."

    Published: 19 Mar 2004
    5
    Medium

    CVE-2004-0361

    Last Modified: 16 Apr 2026

    The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.

    Published: 18 Mar 2004
    7.2
    High

    CVE-2004-0360

    Last Modified: 16 Apr 2026

    Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0239

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0248

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords argument of main.inc.php, (2) body argument of help.inc.php, or (3) the subject field in Personal Messages and Forum.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0265

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0266

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter.

    Published: 18 Mar 2004
    6.4
    Medium

    CVE-2004-0269

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0295

    Last Modified: 16 Apr 2026

    TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.

    Published: 18 Mar 2004
    2.1
    Low

    CVE-2004-0299

    Last Modified: 16 Apr 2026

    Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0303

    Last Modified: 16 Apr 2026

    OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0318

    Last Modified: 16 Apr 2026

    Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0326

    Last Modified: 16 Apr 2026

    Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0335

    Last Modified: 16 Apr 2026

    LAN SUITE Web Mail 602Pro, when configured to use the "Directory browsing" feature, allows remote attackers to obtain a directory listing via an HTTP request to (1) index.html, (2) cgi-bin/, or (3) users/.

    Published: 18 Mar 2004