Skip to main content

Year archive

CVEs published in 2004

Archive summary

2,451 CVEs published in 2004 — 229 Critical, 754 High, 1,265 Medium, 203 Low, 0 Unrated.

CVE-2004-0366

Published May 4, 2004

SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0367

Published May 4, 2004

Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0370

Published May 4, 2004

The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kern…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0371

Published May 4, 2004

Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not properly perform certain consistency checks for cross-realm requests, which allows remote attackers with control of a re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0374

Published May 4, 2004

Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensitive SQL information via an HTTP request ending with the "_…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0376

Published May 4, 2004

oftpd 0.3.6 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command with a large value.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0377

Published May 4, 2004

Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands v…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0379

Published May 4, 2004

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certai…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0380

Published May 4, 2004

The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0381

Published May 4, 2004

mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0382

Published May 4, 2004

Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0383

Published May 4, 2004

Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1993

Published May 4, 2004

The patch to the checklogin function in omail.pl for omail webmail 0.98.5 is incomplete, which allows remote attackers to execute arbitrary commands via shell metacharacters such…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0428

Published May 3, 2004

Unknown vulnerability in CoreFoundation in Mac OS X 10.3.3 and Mac OS X 10.3.3 Server, related to "the handling of an environment variable," has unknown attack vectors and unknown…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1982

Published May 3, 2004

Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1991

Published May 3, 2004

Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1983

Published May 2, 2004

The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a den…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1978

Published Apr 30, 2004

Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1979

Published Apr 30, 2004

Cross-site scripting (XSS) vulnerability in do_search.php in PROPS 0.6.1 allows remote attackers to inject arbitrary HTML or web script via the search_string parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1980

Published Apr 30, 2004

Directory traversal vulnerability in glossary.php in PROPS 0.6.1 allows remote attackers to view arbitrary files via a .. (dot dot) in (1) module or (2) format variables.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,026-2,050 of 2,451 CVEsPage 82 of 99