CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-0104

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

    Published: 18 Feb 2004
    7.5
    High

    CVE-2004-0105

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

    Published: 18 Feb 2004
    5
    Medium

    CVE-2004-0095

    Last Modified: 16 Apr 2026

    McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.

    Published: 17 Feb 2004
    7.5
    High

    CVE-2004-0004

    Last Modified: 16 Apr 2026

    The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote attackers to spoof requests from other users.

    Published: 17 Feb 2004
    7.5
    High

    CVE-2004-0068

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.

    Published: 17 Feb 2004
    10
    Critical

    CVE-2003-0903

    Last Modified: 16 Apr 2026

    Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.

    Published: 17 Feb 2004
    7.5
    High

    CVE-2004-0063

    Last Modified: 16 Apr 2026

    The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number.

    Published: 17 Feb 2004
    7.5
    High

    CVE-2004-0070

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.

    Published: 17 Feb 2004
    6.8
    Medium

    CVE-2004-0049

    Last Modified: 16 Apr 2026

    Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.

    Published: 17 Feb 2004
    5
    Medium

    CVE-2004-1180

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).

    Published: 16 Feb 2004
    5
    Medium

    CVE-2004-0143

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in Nokia 6310(i) Mobile phones allow remote attackers to cause a denial of service (reset) via malformed Bluetooth OBject EXchange (OBEX) messages, probably triggering buffer overflows.

    Published: 14 Feb 2004
    7.5
    High

    CVE-2004-0132

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.

    Published: 14 Feb 2004
    5
    Medium

    CVE-2004-2082

    Last Modified: 16 Apr 2026

    The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.

    Published: 13 Feb 2004
    7.5
    High

    CVE-2004-0082

    Last Modified: 16 Apr 2026

    The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.

    Published: 13 Feb 2004
    7.2
    High

    CVE-2004-0106

    Last Modified: 16 Apr 2026

    Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.

    Published: 13 Feb 2004
    5
    Medium

    CVE-2004-2088

    Last Modified: 16 Apr 2026

    Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.

    Published: 12 Feb 2004
    10
    Critical

    CVE-2004-0084

    Last Modified: 16 Apr 2026

    Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

    Published: 12 Feb 2004
    7.5
    High

    CVE-2004-0110

    Last Modified: 16 Apr 2026

    Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.

    Published: 12 Feb 2004
    7.5
    High

    CVE-2004-0765

    Last Modified: 16 Apr 2026

    The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.

    Published: 12 Feb 2004
    7.5
    High

    CVE-2003-1214

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.

    Published: 11 Feb 2004
    10
    Critical

    CVE-2004-0039

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.

    Published: 11 Feb 2004
    2.6
    Low

    CVE-2004-2083

    Last Modified: 16 Apr 2026

    Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."

    Published: 11 Feb 2004
    5
    Medium

    CVE-2002-1575

    Last Modified: 16 Apr 2026

    cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email message.

    Published: 11 Feb 2004
    7.5
    High

    CVE-2003-0818

    Last Modified: 16 Apr 2026

    Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.

    Published: 11 Feb 2004
    4.6
    Medium

    CVE-2004-0103

    Last Modified: 16 Apr 2026

    crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.

    Published: 11 Feb 2004
    7.5
    High

    CVE-2004-0078

    Last Modified: 16 Apr 2026

    Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.

    Published: 11 Feb 2004
    5
    Medium

    CVE-2004-2091

    Last Modified: 16 Apr 2026

    Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.

    Published: 10 Feb 2004
    4.6
    Medium

    CVE-2004-2093

    Last Modified: 16 Apr 2026

    Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user. Therefore this issue may be REJECTED in the future.

    Published: 9 Feb 2004
    5
    Medium

    CVE-2004-2080

    Last Modified: 16 Apr 2026

    Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.

    Published: 9 Feb 2004
    7.5
    High

    CVE-2004-2079

    Last Modified: 16 Apr 2026

    Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.

    Published: 9 Feb 2004
    5
    Medium

    CVE-2004-2078

    Last Modified: 16 Apr 2026

    Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.

    Published: 9 Feb 2004
    4.6
    Medium

    CVE-2004-2092

    Last Modified: 16 Apr 2026

    eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information.

    Published: 9 Feb 2004
    5
    Medium

    CVE-2003-0991

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.

    Published: 9 Feb 2004
    7.5
    High

    CVE-2004-2087

    Last Modified: 16 Apr 2026

    Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.

    Published: 8 Feb 2004
    7.5
    High

    CVE-2004-1244

    Last Modified: 16 Apr 2026

    Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

    Published: 8 Feb 2004
    5
    Medium

    CVE-2004-2077

    Last Modified: 16 Apr 2026

    Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.

    Published: 8 Feb 2004
    10
    Critical

    CVE-2004-0083

    Last Modified: 16 Apr 2026

    Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

    Published: 8 Feb 2004
    5
    Medium

    CVE-2004-2090

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via the VBScript LoadPicture method, which returns an error code if the file does not exist.

    Published: 7 Feb 2004
    4.3
    Medium

    CVE-2004-2084

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbitrary web script or HTML via the xSearch parameter.

    Published: 7 Feb 2004
    7.2
    High

    CVE-2004-2073

    Last Modified: 16 Apr 2026

    Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.

    Published: 6 Feb 2004
    5
    Medium

    CVE-2004-2089

    Last Modified: 16 Apr 2026

    Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.

    Published: 6 Feb 2004
    5
    Medium

    CVE-2004-2086

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP POST request with a long query parameter.

    Published: 6 Feb 2004
    7.5
    High

    CVE-2004-0127

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.

    Published: 4 Feb 2004
    5
    Medium

    CVE-2004-0130

    Last Modified: 16 Apr 2026

    login.php in phpGedView 2.65 and earlier allows remote attackers to obtain sensitive information via an HTTP request to login.php that does not contain the required username or password parameters, which causes the information to be leaked in an error message.

    Published: 4 Feb 2004
    4.3
    Medium

    CVE-2004-2085

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3) input.php, (4) browse.php, (5) themes/facade/header.php, or (6) themes/phpcc/header.php.

    Published: 4 Feb 2004
    9.8
    Critical

    CVE-2004-0005

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.

    Published: 3 Feb 2004
    7.5
    High

    CVE-2004-0044

    Last Modified: 16 Apr 2026

    Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username.

    Published: 3 Feb 2004
    7.2
    High

    CVE-2003-0994

    Last Modified: 16 Apr 2026

    The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.

    Published: 3 Feb 2004
    5
    Medium

    CVE-2004-0013

    Last Modified: 16 Apr 2026

    jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).

    Published: 3 Feb 2004
    7.2
    High

    CVE-2004-0015

    Last Modified: 16 Apr 2026

    vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows local users to gain privileges.

    Published: 3 Feb 2004