CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2004-0279

    Last Modified: 16 Apr 2026

    AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0280

    Last Modified: 16 Apr 2026

    Caucho Technology Resin 2.1.12 allows remote attackers to view JSP source via an HTTP request to a .jsp file that ends in a "%20" (encoded space character), e.g. index.jsp%20.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0288

    Last Modified: 16 Apr 2026

    Buffer overflow in the UdmDocToTextBuf function in mnoGoSearch 3.2.13 through 3.2.15 could allow remote attackers to execute arbitrary code by indexing a large document.

    Published: 18 Mar 2004
    2.1
    Low

    CVE-2004-0289

    Last Modified: 16 Apr 2026

    Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0290

    Last Modified: 16 Apr 2026

    Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0291

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0286

    Last Modified: 16 Apr 2026

    Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0298

    Last Modified: 16 Apr 2026

    CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0302

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0304

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0305

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0310

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0311

    Last Modified: 16 Apr 2026

    American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0313

    Last Modified: 16 Apr 2026

    Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0321

    Last Modified: 16 Apr 2026

    Team Factor 1.25 and earlier allows remote attackers to cause a denial of service (crash) via a packet that uses a negative number to specify the size of the data block that follows, which causes Team Factor to read unallocated memory.

    Published: 18 Mar 2004
    7.5
    High

    CVE-2004-0323

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0329

    Last Modified: 16 Apr 2026

    FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0331

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0332

    Last Modified: 16 Apr 2026

    Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0338

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0339

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter.

    Published: 18 Mar 2004
    7.2
    High

    CVE-2004-0340

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.

    Published: 18 Mar 2004
    2.1
    Low

    CVE-2004-0341

    Last Modified: 16 Apr 2026

    WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.

    Published: 18 Mar 2004
    6.4
    Medium

    CVE-2004-0344

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0345

    Last Modified: 16 Apr 2026

    Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

    Published: 18 Mar 2004
    7.8
    High

    CVE-2004-0346

    Last Modified: 16 Apr 2026

    Off-by-one buffer overflow in _xlate_ascii_write() in ProFTPD 1.2.7 through 1.2.9rc2p allows local users to gain privileges via a 1024 byte RETR command.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0348

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0349

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.

    Published: 18 Mar 2004
    2.1
    Low

    CVE-2004-0350

    Last Modified: 16 Apr 2026

    SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local users to obtain the private key by factoring.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0355

    Last Modified: 16 Apr 2026

    Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0359

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0262

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0237

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.

    Published: 18 Mar 2004
    7.2
    High

    CVE-2004-0238

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0247

    Last Modified: 16 Apr 2026

    The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0282

    Last Modified: 16 Apr 2026

    Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.

    Published: 18 Mar 2004
    2.1
    Low

    CVE-2004-0283

    Last Modified: 16 Apr 2026

    Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/mailmgr.tmp, or (3) /tmp/mailmgr.sort.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0284

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0292

    Last Modified: 16 Apr 2026

    Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0293

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0294

    Last Modified: 16 Apr 2026

    YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.

    Published: 18 Mar 2004
    4.3
    Medium

    CVE-2004-0314

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in done.jsp in WebzEdit 1.9 and earlier allows remote attackers to execute arbitrary script as other users via the message parameter.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0315

    Last Modified: 16 Apr 2026

    Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.

    Published: 18 Mar 2004
    10
    Critical

    CVE-2004-0317

    Last Modified: 16 Apr 2026

    Buffer overflow in eauth in Load Sharing Facility 4.x, 5.x, and 6.x allows local users or remote attackers within the LSF cluster to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long LSF_From_PC parameter.

    Published: 18 Mar 2004
    6.8
    Medium

    CVE-2004-0337

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.

    Published: 18 Mar 2004
    2.1
    Low

    CVE-2004-0351

    Last Modified: 16 Apr 2026

    Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local users with access to the database to decrypt data.

    Published: 18 Mar 2004
    5
    Medium

    CVE-2004-0352

    Last Modified: 16 Apr 2026

    Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.

    Published: 18 Mar 2004
    7.5
    High

    CVE-2004-0365

    Last Modified: 16 Apr 2026

    The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.

    Published: 18 Mar 2004
    7.5
    High

    CVE-2004-0079

    Last Modified: 16 Apr 2026

    The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

    Published: 17 Mar 2004
    5
    Medium

    CVE-2004-0081

    Last Modified: 16 Apr 2026

    OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

    Published: 17 Mar 2004