Skip to main content

Year archive

CVEs published in 2004

Archive summary

2,451 CVEs published in 2004 — 229 Critical, 754 High, 1,265 Medium, 203 Low, 0 Unrated.

CVE-2004-2004

Published May 6, 2004

The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2005

Published May 6, 2004

Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a l…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1994

Published May 5, 2004

FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1996

Published May 5, 2004

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1998

Published May 5, 2004

The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1999

Published May 5, 2004

Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2000

Published May 5, 2004

SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2001

Published May 5, 2004

ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2002

Published May 5, 2004

Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0618

Published May 4, 2004

Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0781

Published May 4, 2004

Unknown vulnerability in ecartis before 1.0.0 does not properly validate user input, which allows attackers to obtain mailing list passwords.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0782

Published May 4, 2004

Multiple buffer overflows in ecartis before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0149

Published May 4, 2004

Multiple buffer overflows in xboing before 2.4 allow local users to gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0174

Published May 4, 2004

Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0176

Published May 4, 2004

Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) E…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0183

Published May 4, 2004

TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0184

Published May 4, 2004

Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification pay…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0218

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Str…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0219

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Stri…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0220

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, which causes an integer underfl…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0221

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0222

Published May 4, 2004

Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0365

Published May 4, 2004

The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS pac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,001-2,025 of 2,451 CVEsPage 81 of 99