5
    Medium

    CVE-2004-0298

    Last Modified: 27 Dec 2012

    CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.

    Source:intuit e.b.
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0297

    Last Modified: 27 Oct 2016

    Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.

    Source:Johnny Cyberpunk
    Published:1 Sept 2004
    5
    Medium

    CVE-2004-0295

    Last Modified: 28 Dec 2012

    TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.

    Source:SecuriTeam
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0293

    Last Modified: 27 Dec 2012

    Directory traversal vulnerability in ShopCartCGI 2.3 allows remote attackers to retrieve arbitrary files via a .. (dot dot) in a HTTP request to (1) gotopage.cgi or (2) genindexpage.cgi.

    Source:G00db0y
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0292

    Last Modified: 28 Dec 2012

    Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

    Source:badpack3t
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0291

    Last Modified: 27 Dec 2012

    SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.

    Source:BaCkSpAcE
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0290

    Last Modified: 31 Dec 2012

    Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.

    Source:Luigi Auriemma
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0287

    Last Modified: 27 Dec 2012

    Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.

    Source:intuit e.b.
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0286

    Last Modified: 8 Dec 2016

    Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.

    Source:gsicht
    Published:18 Mar 2004
    9.8
    Critical

    CVE-2004-0285

    Last Modified: 22 Nov 2016

    PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.

    Source:Pablo Santana
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0282

    Last Modified: 27 Dec 2012

    Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.

    Source:gsicht
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0281

    Last Modified: 25 Dec 2012

    Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-INF/ directory via an HTTP request for "WEB-INF..", which is equivalent to "WEB-INF" in Windows.

    Source:Wang Yun
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0277

    Last Modified: 11 Dec 2016

    Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.

    Source:shaun2k2
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0276

    Last Modified: 31 Dec 2012

    The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.

    Source:Luigi Auriemma
    Published:1 Sept 2004
    5
    Medium

    CVE-2004-0275

    Last Modified: 27 Dec 2012

    SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.

    Source:G00db0y
    Published:18 Mar 2004
    6.8
    Medium

    CVE-2004-0271

    Last Modified: 26 Dec 2012

    Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web script as other users via (1) the sub_name parameter of dl_showall.asp, (2) the SendTo parameter in Personal Messages, (3) the HTTP_REFERER for down.asp, or (4) the image name of an Avatar in the register form.

    Source:Manuel Lopez
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0270

    Last Modified: 25 Dec 2012

    libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling program.

    Source:Oliver Eikemeier
    Published:1 Sept 2004
    6.4
    Medium

    CVE-2004-0269

    Last Modified: 9 Nov 2012

    SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.

    Source:Albert Puigsech Galicia
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0268

    Last Modified: 26 Dec 2012

    Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.

    Source:Moth7
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0266

    Last Modified: 25 Dec 2012

    SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter.

    Source:Janek Vind
    Published:18 Mar 2004
    6.8
    Medium

    CVE-2004-0265

    Last Modified: 25 Dec 2012

    Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.

    Source:Janek Vind
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0264

    Last Modified: 25 Dec 2012

    palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.

    Source:shaun2k2
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0261

    Last Modified: 25 Dec 2012

    oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.

    Source:Tri Huynh
    Published:1 Sept 2004
    5
    Medium

    CVE-2004-0255

    Last Modified: 25 Dec 2012

    Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.

    Source:intuit
    Published:18 Mar 2004
    6.8
    Medium

    CVE-2004-0254

    Last Modified: 3 Jan 2017

    Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.

    Source:Cheng Peng Su
    Published:18 Mar 2004
    6.8
    Medium

    CVE-2004-0251

    Last Modified: 25 Dec 2012

    Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.

    Source:Shaun Colley
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0249

    Last Modified: 14 Dec 2016

    PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID.

    Source:Manuel L?pez
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0247

    Last Modified: 31 Dec 2012

    The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.

    Source:Luigi Auriemma
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0246

    Last Modified: 24 Dec 2012

    Multiple PHP remote file inclusion vulnerabilities in (1) fonctions.lib.php, (2) derniers_commentaires.php, and (3) admin.php in Les Commentaires 2.0 allow remote attackers to execute arbitrary PHP code via the rep parameter.

    Source:Himeur Nourredine
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0245

    Last Modified: 25 Dec 2012

    Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request with a large or negative Content-Length, which causes an integer divide-by-zero.

    Source:Peter Winter-Smith
    Published:18 Mar 2004
    4.7
    Medium

    CVE-2004-0244

    Last Modified: 24 Dec 2012

    Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.

    Source:blackangels
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0242

    Last Modified: 24 Dec 2012

    X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command.

    Source:Philip
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0241

    Last Modified: 24 Dec 2012

    X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php.

    Source:Philip
    Published:18 Mar 2004
    10
    Critical

    CVE-2004-0239

    Last Modified: 23 Jul 2010

    SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

    Source:CoBRa_21
    Published:18 Mar 2004
    7.2
    High

    CVE-2004-0238

    Last Modified: 6 Sept 2016

    Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.

    Source:pi3ki31ny
    Published:18 Mar 2004
    5
    Medium

    CVE-2004-0237

    Last Modified: 24 Dec 2012

    Directory traversal vulnerability in index.php in Aprox PHP Portal allows remote attackers to read arbitrary files via a full pathname in the show parameter.

    Source:Zero X
    Published:18 Mar 2004
    2.1
    Low

    CVE-2004-0233

    Last Modified: 10 Jan 2013

    Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.

    Source:Steve Grubb
    Published:3 Apr 2004
    5
    Medium

    CVE-2004-0230

    Last Modified: 16 Nov 2017

    TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

    Source:Paul A. Watson
    Published:5 May 2004
    7.2
    High

    CVE-2004-0228

    Last Modified: 11 Jan 2013

    Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges.

    Source:Brad Spengler
    Published:3 Jun 2004
    10
    Critical

    CVE-2004-0214

    Last Modified: 12 Jan 2013

    Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.

    Source:Rodrigo Gutierrez
    Published:16 Oct 2004
    7.8
    High

    CVE-2004-0213

    Last Modified: 16 Apr 2026

    Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.

    Source:bkbll
    Published:14 Jul 2004
    10
    Critical

    CVE-2004-0212

    Last Modified: 28 Mar 2019

    Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.

    Source:anonymous
    Published:14 Jul 2004
    7.8
    High

    CVE-2004-0210

    Last Modified: 21 Jan 2013

    The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

    Source:bkbll
    Published:14 Jul 2004
    10
    Critical

    CVE-2004-0209

    Last Modified: 31 Jan 2017

    Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."

    Source:houseofdabus
    Published:16 Oct 2004
    7.5
    High

    CVE-2004-0206

    Last Modified: 7 Mar 2011

    Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.

    Source:Metasploit
    Published:16 Oct 2004
    7.5
    High

    CVE-2004-0204

    Last Modified: 13 Jan 2013

    Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.

    Source:Imperva Application Defense Center
    Published:11 Jun 2004
    9.3
    Critical

    CVE-2004-0200

    Last Modified: 16 Apr 2026

    Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.

    Source:perplexy
    Published:17 Sept 2004
    7.5
    High

    CVE-2004-0194

    Last Modified: 24 Jul 2011

    Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data Format (XFDF) data.

    Source:extraexploit
    Published:29 Mar 2004
    6.8
    Medium

    CVE-2004-0192

    Last Modified: 31 Dec 2012

    Cross-site scripting (XSS) vulnerability in the Management Service for Symantec Gateway Security 2.0 allows remote attackers to steal cookies and hijack a management session via a /sgmi URL that contains malicious script, which is not quoted in the resulting error page.

    Source:Soby
    Published:4 Mar 2004
    7.5
    High

    CVE-2004-0189

    Last Modified: 31 Dec 2012

    The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.

    Source:Mitch Adair
    Published:29 Feb 2004