6.8
    Medium

    CVE-2004-1210

    Last Modified: 15 Mar 2013

    Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables.

    Source:Paul Kurczaba
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1208

    Last Modified: 16 Apr 2026

    Buffer overflow in Orbz 2.10 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long password field in a join request.

    Source:Luigi Auriemma
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1207

    Last Modified: 16 Apr 2026

    The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero.

    Source:Luigi Auriemma
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1206

    Last Modified: 14 Mar 2013

    Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter.

    Source:John Cobb
    Published:15 Dec 2004
    6.8
    Medium

    CVE-2004-1196

    Last Modified: 14 Mar 2013

    Cross-site scripting (XSS) vulnerability in inmail.pl in Insite Inmail allows remote attackers to inject arbitrary web script or HTML via the acao parameter.

    Source:Carlos Ulver
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1195

    Last Modified: 16 Apr 2026

    Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.

    Source:Luigi Auriemma
    Published:15 Dec 2004
    5
    Medium

    CVE-2004-1194

    Last Modified: 16 Apr 2026

    Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.

    Source:Luigi Auriemma
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1192

    Last Modified: 5 Dec 2016

    Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.

    Source:CoKi
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1172

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitrary code via a registration request with a long hostname.

    Source:class101
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1170

    Last Modified: 27 Jan 2013

    a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

    Source:Rudolf Polzer
    Published:10 Dec 2004
    7.5
    High

    CVE-2004-1166

    Last Modified: 15 Mar 2013

    CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

    Source:Albert Puigsech Galicia
    Published:10 Dec 2004
    7.5
    High

    CVE-2004-1165

    Last Modified: 15 Mar 2013

    Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

    Source:Albert Puigsech Galicia
    Published:5 Dec 2004
    7.5
    High

    CVE-2004-1161

    Last Modified: 15 Mar 2013

    rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.

    Source:Jason Wies
    Published:10 Dec 2004
    5.1
    Medium

    CVE-2004-1150

    Last Modified: 28 Apr 2013

    Stack-based buffer overflow in the in_cdda.dll plugin for Winamp 5.0 through 5.08c allows attackers to execute arbitrary code via a cda:// URL with a long (1) device name or (2) sound track number, as demonstrated with a .m3u or .pls playlist file.

    Source:Yu Yang
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-1147

    Last Modified: 17 Mar 2013

    phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters.

    Source:Nicolas Gregoire
    Published:15 Dec 2004
    10
    Critical

    CVE-2004-1137

    Last Modified: 19 Apr 2016

    Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local and remote attackers to cause a denial of service or execute arbitrary code via (1) the ip_mc_source function, which decrements a counter to -1, or (2) the igmp_marksources function, which does not properly validate IGMP message parameters and performs an out-of-bounds read.

    Source:Paul Starzetz
    Published:14 Dec 2004
    5
    Medium

    CVE-2004-1135

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.

    Source:NoPh0BiA
    Published:8 Dec 2004
    10
    Critical

    CVE-2004-1134

    Last Modified: 7 Mar 2011

    Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.

    Source:Metasploit
    Published:8 Dec 2004
    10
    Critical

    CVE-2004-1127

    Last Modified: 14 Mar 2013

    Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command.

    Source:Donato Ferrante
    Published:5 Dec 2004
    5
    Medium

    CVE-2004-1121

    Last Modified: 11 Mar 2013

    Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.

    Source:Gilbert Verdian
    Published:1 Nov 2004
    10
    Critical

    CVE-2004-1120

    Last Modified: 19 Apr 2016

    Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.

    Source:Serkan Akpolat
    Published:1 Dec 2004
    10
    Critical

    CVE-2004-1119

    Last Modified: 27 Apr 2011

    Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist file.

    Source:k-otik
    Published:1 Dec 2004
    10
    Critical

    CVE-2004-1118

    Last Modified: 16 Apr 2026

    Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.

    Source:Komrade
    Published:1 Dec 2004
    5
    Medium

    CVE-2004-1109

    Last Modified: 16 Apr 2026

    The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.

    Source:houseofdabus
    Published:1 Dec 2004
    7.5
    High

    CVE-2004-1104

    Last Modified: 11 Mar 2013

    Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page that contains a BASE element that points to the legitimate site, followed by an anchor (a) element with an empty "href" attribute, and a FORM whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL.

    Source:http-equiv
    Published:1 Dec 2004
    5
    Medium

    CVE-2004-1102

    Last Modified: 11 Mar 2013

    MailPost 5.1.1sv, and possibly earlier versions, displays a different error message depending on whether the requested file exists or not, which allows remote attackers to gain sensitive information.

    Source:Gemma Hughes
    Published:1 Dec 2004
    5.8
    Medium

    CVE-2004-1101

    Last Modified: 11 Mar 2013

    mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash), leak sensitive pathname information in the resulting error message, and execute a cross-site scripting (XSS) attack via an HTTP request that contains a / (backslash) and arbitrary webscript before the requested file, which leaks the pathname and does not quote the script in the resulting Visual Basic error message.

    Source:Procheckup
    Published:1 Dec 2004
    6.8
    Medium

    CVE-2004-1100

    Last Modified: 11 Mar 2013

    Cross-site scripting (XSS) vulnerability in mailpost.exe in MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to execute arbitrary web script or HTML via the append parameter.

    Source:Procheckup
    Published:1 Dec 2004
    7.5
    High

    CVE-2004-1096

    Last Modified: 16 Apr 2026

    Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

    Source:oc192
    Published:1 Dec 2004
    10
    Critical

    CVE-2004-1095

    Last Modified: 14 Aug 2017

    Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.

    Source:infamous41md
    Published:1 Dec 2004
    10
    Critical

    CVE-2004-1080

    Last Modified: 16 Apr 2026

    The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."

    Source:class101
    Published:1 Dec 2004
    6.8
    Medium

    CVE-2004-1075

    Last Modified: 14 Mar 2013

    Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote attackers to inject arbitrary HTML and web script via a malformed URL, which is not properly cleansed when generating an error message.

    Source:Jeremy Bae
    Published:1 Dec 2004
    2.1
    Low

    CVE-2004-1074

    Last Modified: 14 Mar 2013

    The binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial of service (kernel oops) via a malformed a.out binary.

    Source:Florian Heinz
    Published:11 Nov 2004
    2.1
    Low

    CVE-2004-1073

    Last Modified: 4 Sept 2016

    The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.

    Source:Paul Starzetz
    Published:10 Nov 2004
    5
    Medium

    CVE-2004-1060

    Last Modified: 21 May 2013

    Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

    Source:Fernando Gont
    Published:12 Apr 2004
    7.2
    High

    CVE-2004-1054

    Last Modified: 30 Jan 2017

    Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.

    Source:cees-bart
    Published:22 Dec 2004
    10
    Critical

    CVE-2004-1050

    Last Modified: 12 Apr 2016

    Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."

    Source:Skylined
    Published:18 Nov 2004
    5
    Medium

    CVE-2004-1043

    Last Modified: 21 Apr 2016

    Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."

    Source:Paul
    Published:31 Dec 2004
    10
    Critical

    CVE-2004-1037

    Last Modified: 19 Apr 2016

    The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.

    Source:RoMaNSoFt
    Published:19 Nov 2004
    9.3
    Critical

    CVE-2004-1029

    Last Modified: 13 Mar 2013

    The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

    Source:Jouko Pynnonen
    Published:24 Nov 2004
    5
    Medium

    CVE-2004-1020

    Last Modified: 25 Apr 2013

    The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP applications that contain a directory traversal vulnerability in require or include statements, but are otherwise protected by the magic_quotes_gpc mechanism. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

    Source:Daniel Fabian
    Published:8 Dec 2004
    10
    Critical

    CVE-2004-1018

    Last Modified: 8 Dec 2016

    Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial of service, or execute arbitrary code via (1) a negative offset value to the shmop_write function, (2) an "integer overflow/underflow" in the pack function, or (3) an "integer overflow/underflow" in the unpack function. NOTE: this issue was originally REJECTed by its CNA before publication, but that decision is in active dispute. This candidate may change significantly in the future as a result of further discussion.

    Source:Stefan Esser
    Published:8 Dec 2004
    2.1
    Low

    CVE-2004-1016

    Last Modified: 4 Sept 2016

    The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

    Source:Paul Starzetz
    Published:8 Dec 2004
    5
    Medium

    CVE-2004-1003

    Last Modified: 11 Mar 2013

    Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf file.

    Source:DokFLeed
    Published:4 Nov 2004
    2.1
    Low

    CVE-2004-0996

    Last Modified: 13 Mar 2013

    main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.

    Source:Gangstuck
    Published:1 Dec 2004
    10
    Critical

    CVE-2004-0990

    Last Modified: 12 Apr 2016

    Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

    Source:anonymous
    Published:26 Oct 2004
    10
    Critical

    CVE-2004-0989

    Last Modified: 10 Mar 2013

    Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.

    Source:Sean
    Published:26 Oct 2004
    10
    Critical

    CVE-2004-0964

    Last Modified: 26 Apr 2011

    Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.

    Source:Hakxer
    Published:20 Oct 2004
    5
    Medium

    CVE-2004-0958

    Last Modified: 8 Mar 2013

    php_variables.c in PHP before 5.0.2 allows remote attackers to read sensitive memory contents via (1) GET, (2) POST, or (3) COOKIE GPC variables that end in an open bracket character, which causes PHP to calculate an incorrect string length.

    Source:Stefano Di Paola
    Published:15 Sept 2004
    10
    Critical

    CVE-2004-0953

    Last Modified: 14 Mar 2013

    Buffer overflow in the C2S module in the open source Jabber 2.x server (Jabberd) allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long username.

    Source:icbm
    Published:1 Dec 2004