10
    Critical

    CVE-2004-0648

    Last Modified: 20 Jan 2013

    Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.

    Source:Keith McCanless
    Published:13 Jul 2004
    7.5
    High

    CVE-2004-0641

    Last Modified: 2 Jul 2012

    Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.

    Source:Stealth & S. Krahmer
    Published:5 Aug 2004
    6.8
    Medium

    CVE-2004-0639

    Last Modified: 16 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable or (4) the $event_text variable.

    Source:anonymous
    Published:9 Jul 2004
    6.5
    Medium

    CVE-2004-0637

    Last Modified: 4 Mar 2013

    Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which is publicly accessible.

    Source:Alexander Kornbrust
    Published:2 Sept 2004
    10
    Critical

    CVE-2004-0636

    Last Modified: 30 Mar 2016

    Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.

    Source:mandragore
    Published:12 Aug 2004
    5
    Medium

    CVE-2004-0633

    Last Modified: 20 Jan 2013

    The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.

    Source:Rémi Denis-Courmont
    Published:6 Jul 2004
    10
    Critical

    CVE-2004-0627

    Last Modified: 28 Mar 2016

    The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication via a zero-length scrambled string.

    Source:Eli Kara
    Published:5 Jul 2004
    10
    Critical

    CVE-2004-0621

    Last Modified: 20 Jan 2013

    admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.

    Source:GaMeS
    Published:30 Jun 2004
    4.3
    Medium

    CVE-2004-0620

    Last Modified: 20 Jan 2013

    Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.

    Source:Cheng Peng Su
    Published:30 Jun 2004
    2.1
    Low

    CVE-2004-0618

    Last Modified: 15 Nov 2017

    FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.

    Source:Marceta Milos
    Published:30 Jun 2004
    6.8
    Medium

    CVE-2004-0617

    Last Modified: 20 Jan 2013

    Cross-site scripting (XSS) vulnerability in ArbitroWeb 0.6 allows remote attackers to inject arbitrary script or HTML via the rawURL parameter.

    Source:Josh Gilmour
    Published:30 Jun 2004
    5
    Medium

    CVE-2004-0616

    Last Modified: 20 Jan 2013

    The BT Voyager 2000 Wireless ADSL Router has a default public SNMP community name, which allows remote attackers to obtain sensitive information such as the password, which is stored in plaintext.

    Source:Konstantin V. Gavrilenko
    Published:30 Jun 2004
    5.1
    Medium

    CVE-2004-0615

    Last Modified: 19 Jan 2013

    Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.

    Source:c3rb3r
    Published:30 Jun 2004
    7.5
    High

    CVE-2004-0613

    Last Modified: 19 Jan 2013

    osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.

    Source:Guy Pearce
    Published:30 Jun 2004
    10
    Critical

    CVE-2004-0608

    Last Modified: 6 Mar 2011

    The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.

    Source:Metasploit
    Published:30 Jun 2004
    5
    Medium

    CVE-2004-0605

    Last Modified: 19 Jan 2013

    Non-registered IRC users using (1) ircd-hybrid 7.0.1 and earlier, (2) ircd-ratbox 1.5.1 and earlier, or (3) ircd-ratbox 2.0rc6 and earlier do not have a rate-limit imposed, which could allow remote attackers to cause a denial of service by repeatedly making requests, which are slowly dequeued.

    Source:Erik Sperling Johansen
    Published:30 Jun 2004
    10
    Critical

    CVE-2004-0600

    Last Modified: 6 Sept 2017

    Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.

    Source:Noam Rathaus
    Published:22 Jul 2004
    10
    Critical

    CVE-2004-0597

    Last Modified: 30 Mar 2016

    Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

    Source:anonymous
    Published:4 Aug 2004
    6.8
    Medium

    CVE-2004-0595

    Last Modified: 21 Jan 2013

    The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.

    Source:Stefan Esser
    Published:14 Jul 2004
    5.1
    Medium

    CVE-2004-0594

    Last Modified: 22 Nov 2017

    The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.

    Source:Gyan Chawdhary
    Published:13 Jul 2004
    6.8
    Medium

    CVE-2004-0591

    Last Modified: 19 Jan 2013

    Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.

    Source:Luca Legato
    Published:24 Jun 2004
    5
    Medium

    CVE-2004-0580

    Last Modified: 15 Jan 2013

    DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.

    Source:Jon Hart
    Published:23 Jun 2004
    10
    Critical

    CVE-2004-0575

    Last Modified: 14 Aug 2017

    Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.

    Source:ATmaCA
    Published:16 Oct 2004
    10
    Critical

    CVE-2004-0574

    Last Modified: 16 Apr 2026

    The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.

    Source:Lucas Lavarello
    Published:16 Oct 2004
    7.5
    High

    CVE-2004-0567

    Last Modified: 16 Apr 2026

    The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."

    Source:zuc
    Published:31 Dec 2004
    5
    Medium

    CVE-2004-0558

    Last Modified: 5 Mar 2013

    The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.

    Source:Alvaro Martinez Echevarria
    Published:21 Aug 2004
    10
    Critical

    CVE-2004-0557

    Last Modified: 28 Mar 2016

    Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

    Source:Rave
    Published:28 Jul 2004
    2.1
    Low

    CVE-2004-0554

    Last Modified: 28 Mar 2016

    Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

    Source:lorenzo
    Published:9 Jun 2004
    7.5
    High

    CVE-2004-0552

    Last Modified: 6 Mar 2013

    Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.

    Source:Kurt Seifried
    Published:28 Sept 2004
    10
    Critical

    CVE-2004-0549

    Last Modified: 16 Apr 2026

    The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.

    Source:Ferruh Mavituna
    Published:15 Jun 2004
    7.2
    High

    CVE-2004-0548

    Last Modified: 19 Apr 2016

    Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.

    Source:c0d3r
    Published:11 Jun 2004
    7.2
    High

    CVE-2004-0544

    Last Modified: 3 Jan 2013

    Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.

    Source:watercloud
    Published:10 Jun 2004
    10
    Critical

    CVE-2004-0541

    Last Modified: 6 Mar 2011

    Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

    Source:Metasploit
    Published:8 Jun 2004
    5
    Medium

    CVE-2004-0528

    Last Modified: 15 Jan 2013

    Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

    Source:Lyndon Durham
    Published:8 Jun 2004
    5
    Medium

    CVE-2004-0527

    Last Modified: 15 Jan 2013

    KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

    Source:Drew Copley
    Published:8 Jun 2004
    5
    Medium

    CVE-2004-0526

    Last Modified: 14 Jan 2013

    Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

    Source:http-equiv
    Published:8 Jun 2004
    10
    Critical

    CVE-2004-0524

    Last Modified: 27 Oct 2016

    Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name.

    Source:x314
    Published:8 Jun 2004
    6.8
    Medium

    CVE-2004-0520

    Last Modified: 16 Jan 2013

    Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.

    Source:Roman Medina
    Published:23 May 2004
    6.8
    Medium

    CVE-2004-0519

    Last Modified: 13 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.

    Source:Alvin Alex
    Published:29 Apr 2004
    2.1
    Low

    CVE-2004-0511

    Last Modified: 6 Sept 2019

    Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to cause a denial of service by triggering a null dereference.

    Source:Ramon de C Valle
    Published:28 Oct 2004
    7.2
    High

    CVE-2004-0510

    Last Modified: 6 Sept 2019

    Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.

    Source:Ramon de C Valle
    Published:28 Oct 2004
    5
    Medium

    CVE-2004-0502

    Last Modified: 14 Jan 2013

    Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img tag of the original message, which allows remote attackers to bypass zone restrictions and exploit other issues that rely on predictable locations, as demonstrated using a shell: URI.

    Source:http-equiv
    Published:3 Jun 2004
    5
    Medium

    CVE-2004-0501

    Last Modified: 15 Jan 2013

    Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been read, verify valid e-mail addresses, and possibly leak other information.

    Source:http-equiv
    Published:3 Jun 2004
    2.1
    Low

    CVE-2004-0497

    Last Modified: 28 Nov 2016

    Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.

    Source:Marco Ivaldi
    Published:30 Jun 2004
    6.4
    Medium

    CVE-2004-0493

    Last Modified: 28 Mar 2016

    The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.

    Source:anonymous
    Published:28 Jun 2004
    7.2
    High

    CVE-2004-0490

    Last Modified: 31 Jan 2017

    cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.

    Source:Rob Brown
    Published:3 Jun 2004
    7.6
    High

    CVE-2004-0486

    Last Modified: 15 Jan 2013

    HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.

    Source:Troels Bay
    Published:28 May 2004
    2.6
    Low

    CVE-2004-0484

    Last Modified: 16 Apr 2026

    mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.

    Source:Phuong
    Published:20 May 2004
    5
    Medium

    CVE-2004-0479

    Last Modified: 15 Jan 2013

    Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which triggers a null dereference.

    Source:Mike Mauler
    Published:20 May 2004
    5.1
    Medium

    CVE-2004-0474

    Last Modified: 26 Dec 2012

    Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL. NOTE: since the initial report of this problem, several researchers have been unable to reproduce this issue.

    Source:Bartosz Kwitkowski
    Published:20 May 2004