CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-0016

    Last Modified: 16 Apr 2026

    The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.

    Published: 3 Feb 2004
    7.5
    High

    CVE-2004-0028

    Last Modified: 16 Apr 2026

    jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands.

    Published: 3 Feb 2004
    7.5
    High

    CVE-2004-0045

    Last Modified: 16 Apr 2026

    Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.

    Published: 3 Feb 2004
    7.5
    High

    CVE-2004-1082

    Last Modified: 16 Apr 2026

    mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

    Published: 3 Feb 2004
    10
    Critical

    CVE-2004-0002

    Last Modified: 16 Apr 2026

    The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.

    Published: 3 Feb 2004
    5
    Medium

    CVE-2004-0080

    Last Modified: 16 Apr 2026

    The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.

    Published: 3 Feb 2004
    5
    Medium

    CVE-2003-1207

    Last Modified: 16 Apr 2026

    Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.

    Published: 1 Feb 2004
    4.6
    Medium

    CVE-2004-2133

    Last Modified: 16 Apr 2026

    Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by causing cvsup to link against malicious libraries that are created in world-writable directories such as /usr/src/packages.

    Published: 29 Jan 2004
    2.1
    Low

    CVE-2004-0087

    Last Modified: 16 Apr 2026

    The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a different vulnerability than CVE-2004-0088.

    Published: 29 Jan 2004
    4.6
    Medium

    CVE-2004-0047

    Last Modified: 16 Apr 2026

    Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.

    Published: 29 Jan 2004
    2.1
    Low

    CVE-2004-0088

    Last Modified: 16 Apr 2026

    The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.

    Published: 29 Jan 2004
    7.5
    High

    CVE-2004-2034

    Last Modified: 16 Apr 2026

    Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename.

    Published: 29 Jan 2004
    5
    Medium

    CVE-2004-2132

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter.

    Published: 29 Jan 2004
    10
    Critical

    CVE-2004-0092

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.

    Published: 29 Jan 2004
    5
    Medium

    CVE-2004-0085

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.

    Published: 29 Jan 2004
    5
    Medium

    CVE-2004-0086

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.

    Published: 29 Jan 2004
    4.6
    Medium

    CVE-2004-2134

    Last Modified: 16 Apr 2026

    Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.

    Published: 28 Jan 2004
    7.2
    High

    CVE-2004-2131

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.

    Published: 27 Jan 2004
    5
    Medium

    CVE-2004-2069

    Last Modified: 16 Apr 2026

    sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of service (connection consumption).

    Published: 27 Jan 2004
    5
    Medium

    CVE-2003-1032

    Last Modified: 16 Apr 2026

    Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly involving a buffer overflow.

    Published: 26 Jan 2004
    7.5
    High

    CVE-2004-0006

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.

    Published: 26 Jan 2004
    7.5
    High

    CVE-2004-0007

    Last Modified: 16 Apr 2026

    Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 26 Jan 2004
    7.5
    High

    CVE-2004-0008

    Last Modified: 16 Apr 2026

    Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.

    Published: 26 Jan 2004
    5
    Medium

    CVE-2004-2117

    Last Modified: 16 Apr 2026

    Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a GET request without the HTTP version (HTTP/1.1), or (2) a request without GET or the HTTP version.

    Published: 24 Jan 2004
    4.3
    Medium

    CVE-2004-2122

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters.

    Published: 24 Jan 2004
    5
    Medium

    CVE-2004-2120

    Last Modified: 16 Apr 2026

    Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version.

    Published: 23 Jan 2004
    4.3
    Medium

    CVE-2003-1031

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (2) "Biography", or (3) "Occupation."

    Published: 22 Jan 2004
    4.3
    Medium

    CVE-2004-0091

    Last Modified: 16 Apr 2026

    NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.

    Published: 22 Jan 2004
    4.6
    Medium

    CVE-2004-0074

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.

    Published: 22 Jan 2004
    5
    Medium

    CVE-2004-0096

    Last Modified: 16 Apr 2026

    Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.

    Published: 22 Jan 2004
    10
    Critical

    CVE-2004-1760

    Last Modified: 16 Apr 2026

    The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

    Published: 21 Jan 2004
    5
    Medium

    CVE-2004-1759

    Last Modified: 16 Apr 2026

    Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.

    Published: 21 Jan 2004
    10
    Critical

    CVE-2004-0097

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

    Published: 21 Jan 2004
    7.5
    High

    CVE-2003-0969

    Last Modified: 16 Apr 2026

    mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggering a format string vulnerability.

    Published: 20 Jan 2004
    7.5
    High

    CVE-2003-1022

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory.

    Published: 20 Jan 2004
    7.5
    High

    CVE-2004-0031

    Last Modified: 16 Apr 2026

    PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.

    Published: 20 Jan 2004
    7.5
    High

    CVE-2004-0011

    Last Modified: 16 Apr 2026

    Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.

    Published: 20 Jan 2004
    6.8
    Medium

    CVE-2004-0032

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.

    Published: 20 Jan 2004
    5
    Medium

    CVE-2004-1766

    Last Modified: 16 Apr 2026

    The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing.

    Published: 20 Jan 2004
    5
    Medium

    CVE-2004-2127

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.

    Published: 20 Jan 2004
    5
    Medium

    CVE-2004-0033

    Last Modified: 16 Apr 2026

    admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.

    Published: 20 Jan 2004
    7.5
    High

    CVE-2004-0035

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.

    Published: 20 Jan 2004
    5
    Medium

    CVE-2004-0036

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.

    Published: 20 Jan 2004
    3.7
    Low

    CVE-2003-0924

    Last Modified: 16 Apr 2026

    netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.

    Published: 18 Jan 2004
    5
    Medium

    CVE-2005-2395

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

    Published: 17 Jan 2004
    4.6
    Medium

    CVE-2004-0003

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."

    Published: 16 Jan 2004
    2.1
    Low

    CVE-2004-0058

    Last Modified: 16 Apr 2026

    Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink attack on the .pid_antivir_$$ temporary file.

    Published: 15 Jan 2004
    4.3
    Medium

    CVE-2004-0067

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.

    Published: 15 Jan 2004
    5
    Medium

    CVE-2003-1029

    Last Modified: 16 Apr 2026

    The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when calling print_octets.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2004-0073

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.

    Published: 15 Jan 2004