Skip to main content

Year archive

CVEs published in 2004

Archive summary

2,451 CVEs published in 2004 — 229 Critical, 754 High, 1,265 Medium, 203 Low, 0 Unrated.

CVE-2004-1954

Published Apr 21, 2004

Cross-site scripting (XSS) vulnerability in modules.php in phProfession 2.5 allows remote attackers to inject arbitrary web script or HTML via the jcode parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1956

Published Apr 21, 2004

PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1957

Published Apr 21, 2004

Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Do…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1948

Published Apr 20, 2004

NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information vi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1992

Published Apr 20, 2004

Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1938

Published Apr 19, 2004

SQL injection vulnerability in userlogin.php in Phorum 3.4.7 allows remote attackers to execute arbitrary SQL commands via doubly hex-encoded characters such as "%2527", which is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1941

Published Apr 19, 2004

Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1942

Published Apr 19, 2004

The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows loc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1943

Published Apr 19, 2004

PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1946

Published Apr 19, 2004

Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string speci…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1947

Published Apr 19, 2004

The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1950

Published Apr 19, 2004

phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1576

Published Apr 15, 2004

lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserv…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1577

Published Apr 15, 2004

SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLY…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1578

Published Apr 15, 2004

The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1579

Published Apr 15, 2004

SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0202

Published Apr 15, 2004

The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0257

Published Apr 15, 2004

Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0513

Published Apr 15, 2004

Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0514

Published Apr 15, 2004

Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, whic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0592

Published Apr 15, 2004

Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory tr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0593

Published Apr 15, 2004

Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0594

Published Apr 15, 2004

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0905

Published Apr 15, 2004

Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of serv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,076-2,100 of 2,451 CVEsPage 84 of 99