7.5
    High

    CVE-2004-1784

    Last Modified: 20 Dec 2012

    Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:Peter Winter-Smith
    Published:3 Jan 2004
    7.5
    High

    CVE-2004-1783

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).

    Source:CoolICE
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1782

    Last Modified: 20 Dec 2012

    athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.

    Source:Peter Kieser
    Published:31 Dec 2004
    4.6
    Medium

    CVE-2004-1781

    Last Modified: 19 Dec 2012

    Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CREDITCARD_CHARGE command.

    Source:Rift_XT
    Published:31 Dec 2004
    7.2
    High

    CVE-2004-1774

    Last Modified: 13 May 2013

    Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.

    Source:Esteban Martinez Fayo
    Published:31 Aug 2004
    10
    Critical

    CVE-2004-1770

    Last Modified: 2 Jan 2013

    The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.

    Source:Arab VieruZ
    Published:11 Mar 2004
    10
    Critical

    CVE-2004-1769

    Last Modified: 1 Jan 2013

    The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.

    Source:Arab VieruZ
    Published:11 Mar 2004
    5
    Medium

    CVE-2004-1754

    Last Modified: 19 Jan 2013

    The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query response that contains authoritative or additional records.

    Source:fryxar
    Published:15 Jun 2004
    7.5
    High

    CVE-2004-1752

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header.

    Source:Tan Chew Keong
    Published:24 Aug 2004
    5
    Medium

    CVE-2004-1751

    Last Modified: 16 Apr 2026

    Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet, which generates a "Message too long" socket error that is treated as a critical error.

    Source:Luigi Auriemma
    Published:26 Aug 2004
    2.1
    Low

    CVE-2004-1748

    Last Modified: 27 Jan 2013

    NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.

    Source:Next Generation Security
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1746

    Last Modified: 27 Jan 2013

    Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via the (1) cat_select or (2) show parameters.

    Source:Nikyt0x Argentina
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1745

    Last Modified: 16 Apr 2026

    Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.

    Source:Luigi Auriemma
    Published:24 Aug 2004
    5
    Medium

    CVE-2004-1744

    Last Modified: 5 Jan 2018

    Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests.

    Source:GulfTech Security
    Published:24 Aug 2004
    5
    Medium

    CVE-2004-1742

    Last Modified: 27 Jan 2013

    Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter.

    Source:Jerome Athias
    Published:24 Aug 2004
    5
    Medium

    CVE-2004-1741

    Last Modified: 15 Sept 2017

    Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument, then calling SHOWLIST.

    Source:Tal0n
    Published:23 Aug 2004
    5
    Medium

    CVE-2004-1739

    Last Modified: 16 Apr 2026

    Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.

    Source:Donato Ferrante
    Published:23 Aug 2004
    7.5
    High

    CVE-2004-1737

    Last Modified: 26 Jan 2013

    SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.

    Source:Fernando Quintero
    Published:16 Aug 2004
    4.3
    Medium

    CVE-2004-1735

    Last Modified: 27 Jan 2013

    Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticated users to inject arbitrary web script or HTML via the description field.

    Source:Jose Antonio
    Published:21 Aug 2004
    5
    Medium

    CVE-2004-1731

    Last Modified: 8 Jun 2018

    signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.

    Source:Jose Antonio
    Published:20 Aug 2004
    7.5
    High

    CVE-2004-1728

    Last Modified: 26 Jan 2013

    Buffer overflow in British National Corpus SARA (sarad) allows remote attackers to execute arbitrary code by calling the client with a long string.

    Source:Matthias Bethke
    Published:20 Aug 2004
    5
    Medium

    CVE-2004-1727

    Last Modified: 5 Jan 2018

    BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.

    Source:GulfTech Security
    Published:20 Aug 2004
    7.5
    High

    CVE-2004-1724

    Last Modified: 26 Jan 2013

    The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.

    Source:Ahmad Muammar
    Published:18 Aug 2004
    7.5
    High

    CVE-2004-1722

    Last Modified: 26 Jan 2013

    SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter.

    Source:Criolabs
    Published:17 Aug 2004
    5
    Medium

    CVE-2004-1720

    Last Modified: 26 Jan 2013

    The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.

    Source:Criolabs
    Published:17 Aug 2004
    4.3
    Medium

    CVE-2004-1719

    Last Modified: 26 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) cserver, (3) ext, (4) global, (5) showgroups, (6) or showlite parameters to address.html, or the (7) spage or (8) autoresponder parameters to settings.html, the (9) folder parameter to readmail.html, or the (10) attachmentpage_text_error parameter to attachment.html, (11) folder, (12) ct, or (13) cv parameters to calendar.html, (14) an <img> tag, or (15) the subject of an e-mail message.

    Source:Criolabs
    Published:17 Aug 2004
    7.5
    High

    CVE-2004-1717

    Last Modified: 30 Mar 2016

    Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value.

    Source:infamous41md
    Published:16 Aug 2004
    7.1
    High

    CVE-2004-1714

    Last Modified: 24 Jan 2013

    BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall rule.

    Source:Paul Craig
    Published:11 Aug 2004
    7.2
    High

    CVE-2004-1707

    Last Modified: 24 Jan 2013

    The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.

    Source:Juan Manuel Pascual Escribá
    Published:30 Jul 2004
    5
    Medium

    CVE-2004-1705

    Last Modified: 16 Apr 2026

    Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.

    Source:CoKi
    Published:30 Jul 2004
    8.8
    High

    CVE-2004-1703

    Last Modified: 24 Jan 2013

    Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.

    Source:Joseph Moniz
    Published:30 Jul 2004
    10
    Critical

    CVE-2004-1701

    Last Modified: 24 Jan 2013

    Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.

    Source:Juan Pablo Martinez Kuhn
    Published:9 Aug 2004
    5
    Medium

    CVE-2004-1699

    Last Modified: 6 Mar 2013

    SettingsBase.php in Pinnacle ShowCenter 1.51 allows remote attackers to cause a denial of service (web interface errors) via an invalid Skin parameter.

    Source:Marc Ruef
    Published:21 Sept 2004
    5
    Medium

    CVE-2004-1698

    Last Modified: 30 Mar 2016

    The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.

    Source:Luigi Auriemma
    Published:24 Sept 2004
    5
    Medium

    CVE-2004-1696

    Last Modified: 5 Jan 2018

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66.

    Source:GulfTech Security
    Published:21 Sept 2004
    10
    Critical

    CVE-2004-1695

    Last Modified: 5 Jan 2018

    EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).

    Source:GulfTech Security
    Published:20 Sept 2004
    7.5
    High

    CVE-2004-1693

    Last Modified: 6 Mar 2013

    PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.

    Source:Joxean Koret
    Published:18 Sept 2004
    4.3
    Medium

    CVE-2004-1692

    Last Modified: 6 Mar 2013

    Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.

    Source:Joxean Koret
    Published:18 Sept 2004
    5
    Medium

    CVE-2004-1691

    Last Modified: 5 Jan 2018

    The Web Server in DNS4Me 3.0.0.4 allows remote attackers to cause a denial of service (CPU consumption and crash) via a large amount of data.

    Source:GulfTech Security
    Published:18 Sept 2004
    2.1
    Low

    CVE-2004-1689

    Last Modified: 30 Mar 2016

    sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbitrary files via a symlink attack on the temporary file before quitting sudoedit.

    Source:Angelo Rosiello
    Published:16 Sept 2004
    5
    Medium

    CVE-2004-1688

    Last Modified: 16 Apr 2026

    Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sent to port 3103.

    Source:Luigi Auriemma
    Published:16 Sept 2004
    5
    Medium

    CVE-2004-1687

    Last Modified: 6 Mar 2013

    CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.

    Source:Maestro De-Seguridad
    Published:16 Sept 2004
    7.2
    High

    CVE-2004-1681

    Last Modified: 5 Mar 2013

    Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.

    Source:Julio Cesar Fort
    Published:26 Aug 2004
    5
    Medium

    CVE-2004-1678

    Last Modified: 5 Mar 2013

    Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.

    Source:Nikyt0x Argentina
    Published:13 Sept 2004
    5
    Medium

    CVE-2004-1675

    Last Modified: 26 Dec 2016

    Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.

    Source:str0ke
    Published:11 Sept 2004
    7.5
    High

    CVE-2004-1666

    Last Modified: 30 Mar 2016

    Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character.

    Source:Komrade
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1665

    Last Modified: 4 Mar 2013

    Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.

    Source:Michal Blaszczak
    Published:5 Sept 2004
    5
    Medium

    CVE-2004-1664

    Last Modified: 16 Apr 2026

    Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430.

    Source:Luigi Auriemma
    Published:5 Sept 2004
    7.5
    High

    CVE-2004-1661

    Last Modified: 4 Mar 2013

    MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."

    Source:Paul Craig
    Published:2 Sept 2004
    4.3
    Medium

    CVE-2004-1659

    Last Modified: 4 Mar 2013

    Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.

    Source:Exoduks
    Published:2 Sept 2004