5
    Medium

    CVE-2004-0465

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted files via "..//" sequences in the WCP_USER parameter.

    Source:karak0rsan
    Published:31 Dec 2004
    2.6
    Low

    CVE-2004-0445

    Last Modified: 16 Apr 2026

    The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself.

    Source:houseofdabus
    Published:20 May 2004
    5
    Medium

    CVE-2004-0437

    Last Modified: 9 Nov 2016

    Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a "LIST -L" command, which causes Titan to access an invalid socket.

    Source:storm
    Published:6 May 2004
    5.1
    Medium

    CVE-2004-0430

    Last Modified: 5 Dec 2016

    Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.

    Source:Dino Dai Zovi
    Published:6 May 2004
    7.2
    High

    CVE-2004-0424

    Last Modified: 28 Mar 2016

    Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.

    Source:Julien Tinnes
    Published:20 Apr 2004
    10
    Critical

    CVE-2004-0416

    Last Modified: 16 Nov 2017

    Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

    Source:Gyan Chawdhary
    Published:9 Jun 2004
    2.1
    Low

    CVE-2004-0415

    Last Modified: 28 Mar 2016

    Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.

    Source:Paul Starzetz
    Published:3 Aug 2004
    7.5
    High

    CVE-2004-0409

    Last Modified: 28 Mar 2016

    Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.

    Source:vade79
    Published:5 Apr 2004
    7.5
    High

    CVE-2004-0399

    Last Modified: 14 Jan 2013

    Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.

    Source:newroot
    Published:12 May 2004
    7.5
    High

    CVE-2004-0397

    Last Modified: 22 Nov 2017

    Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.

    Source:Gyan Chawdhary
    Published:28 May 2004
    7.5
    High

    CVE-2004-0396

    Last Modified: 5 Dec 2016

    Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.

    Source:Ac1dB1tCh3z
    Published:19 May 2004
    10
    Critical

    CVE-2004-0393

    Last Modified: 19 Jan 2013

    Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.

    Published:30 Jun 2004
    7.5
    High

    CVE-2004-0390

    Last Modified: 26 Aug 2012

    SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an X session via other X login methods.

    Source:Richard Johnson
    Published:31 Dec 2004
    7.5
    High

    CVE-2004-0389

    Last Modified: 10 Jan 2013

    RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests.

    Source:anonymous
    Published:17 Apr 2004
    10
    Critical

    CVE-2004-0386

    Last Modified: 24 Nov 2016

    Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.

    Source:blexim
    Published:7 Apr 2004
    10
    Critical

    CVE-2004-0380

    Last Modified: 27 Dec 2012

    The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."

    Source:anonymous
    Published:6 Apr 2004
    5
    Medium

    CVE-2004-0375

    Last Modified: 9 Jan 2013

    SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option followed by a length of zero.

    Source:eEye Digital Security Team
    Published:5 May 2004
    6.4
    Medium

    CVE-2004-0374

    Last Modified: 5 Jan 2013

    Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "__SQLUSER__" string.

    Source:anonymous
    Published:6 Apr 2004
    7.5
    High

    CVE-2004-0363

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.

    Source:Metasploit
    Published:23 Mar 2004
    7.5
    High

    CVE-2004-0362

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

    Source:Metasploit
    Published:23 Mar 2004
    5
    Medium

    CVE-2004-0361

    Last Modified: 31 Dec 2012

    The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.

    Source:kang
    Published:18 Mar 2004
    7.2
    High

    CVE-2004-0360

    Last Modified: 21 Apr 2017

    Unknown vulnerability in passwd(1) in Solaris 8.0 and 9.0 allows local users to gain privileges via unknown attack vectors.

    Source:Marco Ivaldi
    Published:18 Mar 2004
    6.8
    Medium

    CVE-2004-0358

    Last Modified: 31 Dec 2012

    Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed parameter during the newslogo_upload action in admin.php.

    Source:Rafel Ivgi The-Insider
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0354

    Last Modified: 31 Dec 2012

    Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.

    Source:Ulf Harnhammar
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0353

    Last Modified: 31 Dec 2012

    Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.

    Source:CMN
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0349

    Last Modified: 31 Dec 2012

    Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.

    Source:Donato Ferrante
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0348

    Last Modified: 31 Dec 2012

    SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.

    Source:Nick Gudov
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0345

    Last Modified: 16 Apr 2026

    Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

    Source:Luigi Auriemma
    Published:18 Mar 2004
    6.4
    Medium

    CVE-2004-0344

    Last Modified: 31 Dec 2012

    Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.

    Source:Alnitak & BackSpace
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0343

    Last Modified: 31 Dec 2012

    Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

    Source:Alnitak & BackSpace
    Published:18 Mar 2004
    7.2
    High

    CVE-2004-0340

    Last Modified: 16 Mar 2016

    Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.

    Source:rdxaxl
    Published:18 Mar 2004
    6.8
    Medium

    CVE-2004-0337

    Last Modified: 31 Dec 2012

    Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed by a / (slash) and the desired script. NOTE: the vendor states that this bug could not be reproduced, so this issue may be REJECTed in the future.

    Source:Rafel Ivgi The-Insider
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0333

    Last Modified: 28 Mar 2016

    Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.

    Source:snooq
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0330

    Last Modified: 27 Oct 2016

    Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.

    Source:saintjmf
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0327

    Last Modified: 11 Sept 2012

    Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.

    Source:Dave Wilson
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0326

    Last Modified: 10 Mar 2011

    Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.

    Source:Metasploit
    Published:18 Mar 2004
    2.1
    Low

    CVE-2004-0325

    Last Modified: 29 Dec 2012

    TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty".

    Source:intuit bug_hunter
    Published:18 Mar 2004
    7.5
    High

    CVE-2004-0323

    Last Modified: 30 Dec 2012

    Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in stats.php. NOTE: it has also been shown that item (3) is also in XMB 1.9 beta.

    Source:Janek Vind
    Published:18 Mar 2004
    4.3
    Medium

    CVE-2004-0322

    Last Modified: 30 Dec 2012

    Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is allowed, or (5) img tag where bbcode is allowed.

    Source:Janek Vind
    Published:23 Feb 2004
    6.8
    Medium

    CVE-2004-0319

    Last Modified: 30 Dec 2012

    Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.

    Source:Cheng Peng Su
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0318

    Last Modified: 30 Dec 2012

    Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.

    Source:Tomasz Grabowski
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0313

    Last Modified: 27 Oct 2016

    Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.

    Source:Metasploit
    Published:18 Mar 2004
    6.4
    Medium

    CVE-2004-0312

    Last Modified: 28 Dec 2012

    Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/write communtiy strings via a query for OID 1.3.6.1.4.1.3955.2.1.13.1.2.

    Source:NN Poster
    Published:18 Mar 2004
    6.8
    Medium

    CVE-2004-0305

    Last Modified: 29 Dec 2012

    Cross-site scripting (XSS) vulnerability in error.asp in WebCortex WebStores 2000 6.0 allows remote attackers to execute arbitrary script as other users and steal session IDs via the Message_id parameter.

    Source:Nick Gudov
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0304

    Last Modified: 14 Nov 2012

    SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.

    Source:Bosen
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0303

    Last Modified: 28 Dec 2012

    OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

    Source:G00db0y
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0302

    Last Modified: 28 Dec 2012

    Directory traversal vulnerability in OWLS 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter in index.php, (2) editfile in glossary.php, or (3) editfile in newmultiplechoice.php.

    Source:G00db0y
    Published:18 Mar 2004
    6.8
    Medium

    CVE-2004-0301

    Last Modified: 27 Dec 2012

    Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrary HTML via the id parameter.

    Source:David Sopas Ferreira
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0300

    Last Modified: 28 Dec 2012

    SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorized access via (1) the cat parameter in shop.php, (2) the id parameter in more.php, (3) the cat_manufacturer parameter in shop_by_brand.php, or (4) the id parameter in listing.php.

    Source:G00db0y
    Published:18 Mar 2004
    2.1
    Low

    CVE-2004-0299

    Last Modified: 28 Dec 2012

    Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters.

    Source:intuit e.b.
    Published:18 Mar 2004