4.3
    Medium

    CVE-2004-1657

    Last Modified: 27 Jan 2013

    Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.

    Source:Dominick Baier
    Published:1 Sept 2004
    5
    Medium

    CVE-2004-1656

    Last Modified: 27 Jan 2013

    CRLF injection vulnerability in Comersus Shopping Cart 5.0991 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the redirecturl parameter.

    Source:Maestro De-Seguridad
    Published:1 Sept 2004
    4.3
    Medium

    CVE-2004-1655

    Last Modified: 5 Jan 2018

    Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the comments module or (2) the subject or message fields in the notes module.

    Source:GulfTech Security
    Published:1 Sept 2004
    7.5
    High

    CVE-2004-1650

    Last Modified: 16 Apr 2026

    D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.

    Source:anonymous
    Published:31 Aug 2004
    7.5
    High

    CVE-2004-1647

    Last Modified: 27 Jan 2013

    SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.

    Source:Criolabs
    Published:30 Aug 2004
    5
    Medium

    CVE-2004-1646

    Last Modified: 5 Jan 2018

    Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Source:GulfTech Security
    Published:30 Aug 2004
    4.3
    Medium

    CVE-2004-1645

    Last Modified: 5 Jan 2018

    Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.

    Source:GulfTech Security
    Published:30 Aug 2004
    5
    Medium

    CVE-2004-1643

    Last Modified: 27 Jan 2013

    WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.

    Source:lion
    Published:29 Aug 2004
    5
    Medium

    CVE-2004-1642

    Last Modified: 16 Apr 2026

    WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.

    Source:lion
    Published:29 Aug 2004
    5
    Medium

    CVE-2004-1641

    Last Modified: 27 Sept 2016

    Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.

    Source:lion
    Published:29 Aug 2004
    4.3
    Medium

    CVE-2004-1640

    Last Modified: 27 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary web script and HTML via the (1) terme parameter to search.php or (2) letter parameter to letter.php.

    Source:CyruxNET
    Published:28 Aug 2004
    7.5
    High

    CVE-2004-1638

    Last Modified: 27 Oct 2016

    Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command.

    Source:NoPh0BiA
    Published:16 Oct 2004
    10
    Critical

    CVE-2004-1636

    Last Modified: 5 Dec 2016

    Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.

    Source:infamous41md
    Published:26 Oct 2004
    7.5
    High

    CVE-2004-1627

    Last Modified: 6 Nov 2013

    Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command.

    Source:KaGra
    Published:22 Oct 2004
    5
    Medium

    CVE-2004-1626

    Last Modified: 6 Nov 2013

    Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.

    Source:NoPh0BiA
    Published:22 Oct 2004
    5
    Medium

    CVE-2004-1623

    Last Modified: 10 Mar 2013

    The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF.

    Source:HexView
    Published:22 Oct 2004
    7.5
    High

    CVE-2004-1622

    Last Modified: 10 Mar 2013

    SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.

    Source:Florian Rock
    Published:21 Oct 2004
    4.3
    Medium

    CVE-2004-1621

    Last Modified: 10 Mar 2013

    NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature

    Source:Juan C Calderon
    Published:18 Oct 2004
    5
    Medium

    CVE-2004-1620

    Last Modified: 31 Oct 2016

    CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.

    Source:ChaoticEvil
    Published:21 Oct 2004
    7.5
    High

    CVE-2004-1619

    Last Modified: 16 Apr 2026

    Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.

    Source:Luigi Auriemma
    Published:20 Oct 2004
    5
    Medium

    CVE-2004-1612

    Last Modified: 10 Mar 2013

    Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.

    Source:Carl Livitt
    Published:18 Oct 2004
    5
    Medium

    CVE-2004-1602

    Last Modified: 12 Apr 2016

    ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.

    Source:Leon Juranic
    Published:15 Oct 2004
    7.5
    High

    CVE-2004-1601

    Last Modified: 10 Mar 2013

    Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.

    Source:R00tCr4ck
    Published:16 Oct 2004
    7.5
    High

    CVE-2004-1596

    Last Modified: 10 Mar 2013

    The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as passwords and router settings via a direct HTTP request to app_sta.stm.

    Source:Karb0nOxyde
    Published:13 Oct 2004
    7.5
    High

    CVE-2004-1595

    Last Modified: 10 Mar 2011

    Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.

    Source:Metasploit
    Published:13 Oct 2004
    7.5
    High

    CVE-2004-1592

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script.

    Source:Exoduks
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1587

    Last Modified: 16 Apr 2026

    Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1585

    Last Modified: 16 Apr 2026

    Flash Messaging 5.2.0g (rev 1.1.2) and earlier allows remote attackers to cause a denial of service (application crash) via certain wide characters.

    Source:Alberto Ortega Llamas
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1584

    Last Modified: 12 Apr 2016

    CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.

    Source:Tenable NS
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1580

    Last Modified: 4 Nov 2016

    SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:X_AviaTique_X
    Published:31 Dec 2004
    4
    Medium

    CVE-2004-1569

    Last Modified: 19 Jan 2018

    Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that contains long File1 (filename) fields.

    Source:GulfTech Security
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1567

    Last Modified: 30 Mar 2016

    profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.

    Source:CHT Security Research
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1564

    Last Modified: 7 Mar 2013

    CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter.

    Source:Alexander Antipov
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1563

    Last Modified: 7 Mar 2013

    Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php.

    Source:Alexander Antipov
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1562

    Last Modified: 7 Mar 2013

    SQL injection vulnerability in redir_url.php in w-Agora 4.1.6a allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Source:Alexander Antipov
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1561

    Last Modified: 16 Apr 2026

    Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.

    Source:Delikon
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1560

    Last Modified: 7 Mar 2019

    Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.

    Source:securma massine
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1559

    Last Modified: 4 May 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title parameters to bookmarklet.php, (4) cat_ID parameter to categories.php, (5) s parameter to edit.php, or (6) s or mode parameter to edit-comments.php.

    Source:Thomas Waldegger
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1558

    Last Modified: 27 Oct 2016

    Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.

    Source:Metasploit
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1555

    Last Modified: 6 Mar 2013

    Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp.

    Source:pigrelax
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1554

    Last Modified: 7 Mar 2013

    PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.

    Source:Himeur Nourredine
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1553

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.

    Source:e.wiZz!
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-1552

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp.

    Source:parad0x
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1551

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.

    Source:indoushka
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1546

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.

    Source:D_BuG
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1543

    Last Modified: 14 Mar 2013

    Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.

    Source:Jeremy Bae
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1542

    Last Modified: 16 Apr 2026

    Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1540

    Last Modified: 13 Mar 2013

    ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly other versions, with HTTP Remote Administration enabled, does not require a password to access rpFWUpload.html, which allows remote attackers to reset the router configuration file.

    Source:Francisco Canela
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1539

    Last Modified: 16 Apr 2026

    Halo: Combat Evolved 1.05 and earlier allows remote game servers to cause a denial of service (client crash) via a long value in a game server reply, which triggers a NULL dereference.

    Source:Luigi Auriemma
    Published:31 Dec 2004
    4.3
    Medium

    CVE-2004-1537

    Last Modified: 13 Mar 2013

    Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.

    Source:Steve
    Published:31 Dec 2004