Skip to main content

Year archive

CVEs published in 2004

Archive summary

2,451 CVEs published in 2004 — 229 Critical, 754 High, 1,265 Medium, 203 Low, 0 Unrated.

CVE-2004-0090

Published Dec 31, 2004

Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0138

Published Dec 31, 2004

The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architect…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0323

Published Dec 31, 2004

Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) des…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0325

Published Dec 31, 2004

TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr,…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0390

Published Dec 31, 2004

SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which allows remote attackers to gain unauthorized access to an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0429

Published Dec 31, 2004

Unknown vulnerability related to "the handling of large requests" in RAdmin for Apple Mac OS X 10.3.3 and Mac OS X 10.2.8 may allow attackers to have unknown impact via unknown at…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0462

Published Dec 31, 2004

The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those co…

CVSS 2.1 · Low

CVE-2004-0465

Published Dec 31, 2004

Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows remote attackers to read keys within arbitrary INI formatted f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0467

Published Dec 31, 2004

Juniper JUNOS 5.x through JUNOS 7.x allows remote attackers to cause a denial of service (routing disabled) via a large number of MPLS packets, which are not filtered or verified…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0491

Published Dec 31, 2004

The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which all…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0498

Published Dec 31, 2004

The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0555

Published Dec 31, 2004

Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0560

Published Dec 31, 2004

Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted content of a certain size th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0561

Published Dec 31, 2004

Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0592

Published Dec 31, 2004

The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attack…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0638

Published Dec 31, 2004

Buffer overflow in the KSDWRTB function in the dbms_system package (dbms_system.ksdwrt) for Oracle 9i Database Server Release 2 9.2.0.3 and 9.2.0.4, 9i Release 1 9.0.1.4 and 9.0.1…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0780

Published Dec 31, 2004

Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0789

Published Dec 31, 2004

Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite…

CVSS 5.0 · Medium

CVE-2004-0806

Published Dec 31, 2004

cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, w…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0808

Published Dec 31, 2004

The process_logon_packet function in the nmbd server for Samba 3.0.6 and earlier, when domain logons are enabled, allows remote attackers to cause a denial of service via a SAM_UA…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0811

Published Dec 31, 2004

Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 2,451 CVEsPage 1 of 99