7.5
    High

    CVE-2004-1373

    Last Modified: 22 Nov 2017

    Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.

    Source:pucik
    Published:23 Dec 2004
    8.5
    High

    CVE-2004-1364

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.

    Source:Marco Ivaldi
    Published:4 Aug 2004
    2.1
    Low

    CVE-2004-1335

    Last Modified: 4 Sept 2016

    Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.

    Source:Georgi Guninski
    Published:8 Dec 2004
    2.1
    Low

    CVE-2004-1333

    Last Modified: 19 Apr 2016

    Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.

    Source:Georgi Guninski
    Published:15 Dec 2004
    7.2
    High

    CVE-2004-1330

    Last Modified: 16 Apr 2026

    Buffer overflow in paginit in AIX 5.1 through 5.3 allows local users to execute arbitrary code via a long username.

    Source:cees-bart
    Published:31 Dec 2004
    7.2
    High

    CVE-2004-1329

    Last Modified: 30 Jan 2017

    Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd in AIX 5.1 through 5.3 allows local users to execute arbitrary programs by modifying the DIAGNOSTICS environment variable to point to a malicious Dctrl program.

    Source:cees-bart
    Published:20 Dec 2004
    7.5
    High

    CVE-2004-1327

    Last Modified: 19 Apr 2016

    Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a LIST command that contains a file name with a long extension.

    Source:cybertronic
    Published:31 Dec 2004
    7.2
    High

    CVE-2004-1326

    Last Modified: 16 Apr 2026

    Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.

    Source:Kristoffer Brånemyr
    Published:20 Dec 2004
    5
    Medium

    CVE-2004-1325

    Last Modified: 27 Apr 2013

    The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file does not exist and the size of the file if the file exists, which allows remote attackers to determine the existence of files on the local system.

    Source:Arman Nayyeri
    Published:18 Dec 2004
    2.6
    Low

    CVE-2004-1324

    Last Modified: 27 Apr 2013

    The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.

    Source:Arman Nayyeri
    Published:18 Dec 2004
    7.5
    High

    CVE-2004-1317

    Last Modified: 21 Apr 2016

    Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.

    Source:class101
    Published:27 Dec 2004
    7.5
    High

    CVE-2004-1315

    Last Modified: 16 Apr 2026

    viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm.

    Source:Michael Brooks
    Published:12 Nov 2004
    5.1
    Medium

    CVE-2004-1306

    Last Modified: 6 May 2013

    Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.

    Source:flashsky fangxing
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-1305

    Last Modified: 16 Apr 2026

    The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.

    Source:Flashsky
    Published:23 Dec 2004
    10
    Critical

    CVE-2004-1304

    Last Modified: 24 Apr 2013

    Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.

    Source:anonymous
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1303

    Last Modified: 30 Apr 2013

    Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code via crafted HTTP responses.

    Source:Ariel Berkman
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1301

    Last Modified: 30 Apr 2013

    Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a crafted Excel (XLS) file.

    Source:Kris Kubicki
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1300

    Last Modified: 30 Apr 2013

    Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to execute arbitrary code via a crafted AIFF file.

    Source:Ariel Berkman
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1299

    Last Modified: 30 Apr 2013

    Buffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted web page.

    Source:Ariel Berkman
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1298

    Last Modified: 30 Apr 2013

    Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a crafted FRM file.

    Source:Qiao Zhang
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1293

    Last Modified: 30 Apr 2013

    Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitrary code via a crafted RTF file.

    Source:Limin Wang
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1292

    Last Modified: 30 Apr 2013

    Buffer overflow in the parse_emelody function in parse_emelody.c for ringtonetools 2.22 allows remote attackers to execute arbitrary code via a crafted eMelody file.

    Source:Qiao Zhang
    Published:22 Dec 2004
    7.5
    High

    CVE-2004-1291

    Last Modified: 25 Apr 2013

    Buffer overflow in qwik-smtpd allows remote attackers to use the server as an SMTP spam relay via a long HELO command, which overwrites the adjacent localIP data buffer.

    Source:Jonathan Rockway
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1289

    Last Modified: 30 Apr 2013

    Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file.

    Source:Danny Lungstrom
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1288

    Last Modified: 30 Apr 2013

    Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file.

    Source:Wiktor Kopec
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1287

    Last Modified: 30 Apr 2013

    Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.

    Source:Jonathan Rockway
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1286

    Last Modified: 18 Mar 2013

    Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows remote attackers to execute arbitrary code via a crafted gnutella response.

    Source:Bartlomiej Sieka
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1284

    Last Modified: 24 Apr 2013

    Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.

    Source:Bartlomiej Sieka
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1282

    Last Modified: 30 Apr 2013

    Buffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary code via a crafted message that is not properly handled during a Reply operation.

    Source:Stephen Dranger
    Published:22 Dec 2004
    5
    Medium

    CVE-2004-1269

    Last Modified: 25 Apr 2013

    lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.

    Source:Bartlomiej Sieka
    Published:15 Dec 2004
    6.5
    Medium

    CVE-2004-1267

    Last Modified: 3 Feb 2017

    Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.

    Source:Ariel Berkman
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1264

    Last Modified: 24 Apr 2013

    Buffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code via a crafted chbg scenario file.

    Source:Danny Lungstrom
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1261

    Last Modified: 30 Apr 2013

    Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code via crafted ASP scripts.

    Source:Qiao Zhang
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1260

    Last Modified: 30 Apr 2013

    Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abctab2ps 1.6.3 allow remote attackers to execute arbitrary code via crafted ABC files.

    Source:Limin Wang
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1259

    Last Modified: 30 Apr 2013

    Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute arbitrary code via crafted ABC files.

    Source:Yosef Klein
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1256

    Last Modified: 30 Apr 2013

    Multiple buffer overflows in the (1) event_text and (2) event_specific functions in abc2midi 2004.12.04 allow remote attackers to execute arbitrary code via crafted ABC files.

    Source:Limin Wang
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1254

    Last Modified: 19 Apr 2016

    WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.

    Source:Vafa Khoshaein
    Published:22 Dec 2004
    6.2
    Medium

    CVE-2004-1235

    Last Modified: 23 Nov 2016

    Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.

    Source:Tim Hsu
    Published:6 Jan 2005
    10
    Critical

    CVE-2004-1227

    Last Modified: 5 Jan 2018

    Directory traversal vulnerability in SugarCRM Sugar Sales 2.0.1c and earlier allows remote attackers to read arbitrary files and possibly execute arbitrary PHP code via .. (dot dot) sequences in the (1) module, (2) action, or (3) theme parameters to index.php, (4) the theme parameter to Login.php, and possibly other parameters or scripts.

    Source:GulfTech Security
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1225

    Last Modified: 5 Jan 2018

    SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via the record parameter in a DetailView action to index.php, and record parameters in other functionality.

    Source:GulfTech Security
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1223

    Last Modified: 15 Mar 2013

    The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as the absolute path for the web server, via an HTTP request to fsmsh.dll without any parameters.

    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1221

    Last Modified: 15 Mar 2013

    Directory traversal vulnerability in weblibs.pl in WebLibs 1.0 allows remote attackers to read arbitrary files via .. sequences in the TextFile parameter.

    Source:John Bissell
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1220

    Last Modified: 16 Apr 2026

    Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference.

    Source:Luigi Auriemma
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1217

    Last Modified: 16 Apr 2026

    Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.

    Source:Mouse
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1216

    Last Modified: 16 Apr 2026

    The scripts that handle players in Kreed 1.05 and earlier allow remote attackers to cause a denial of service (server freeze) via a long (1) nickname or (2) model type, which generates dialog boxes on the server that must be manually handled before the server continues the game.

    Source:Luigi Auriemma
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1215

    Last Modified: 16 Apr 2026

    Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a "message too long" socket error.

    Source:Luigi Auriemma
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1214

    Last Modified: 16 Apr 2026

    Format string vulnerability in Kreed 1.05 and earlier allows remote attackers to execute arbitrary code via format specifiers in (1) a nickname or (2) message text.

    Source:Luigi Auriemma
    Published:15 Dec 2004
    6.8
    Medium

    CVE-2004-1213

    Last Modified: 15 Mar 2013

    Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter.

    Source:Emile van Elen
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1212

    Last Modified: 15 Mar 2013

    Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument.

    Source:Steve Kemp
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1211

    Last Modified: 25 May 2016

    Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.

    Source:Reed Arvin
    Published:15 Dec 2004