Skip to main content

Year archive

CVEs published in 2004

Archive summary

2,451 CVEs published in 2004 — 229 Critical, 754 High, 1,265 Medium, 203 Low, 0 Unrated.

CVE-2004-1934

Published Apr 15, 2004

PHP remote file inclusion vulnerability in affich.php in Gemitel 3.50 allows remote attackers to execute arbitrary PHP code via the base parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1935

Published Apr 15, 2004

Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1936

Published Apr 14, 2004

ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1939

Published Apr 14, 2004

Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.0 allows remote attackers to inject arbitrary web script or HTML via double encoded slashes (%252F) in the key paramete…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1944

Published Apr 14, 2004

Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1756

Published Apr 13, 2004

BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1758

Published Apr 13, 2004

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection poo…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1929

Published Apr 13, 2004

SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1060

Published Apr 12, 2004

Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1925

Published Apr 12, 2004

Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1928

Published Apr 12, 2004

The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1930

Published Apr 12, 2004

Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1932

Published Apr 12, 2004

SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1933

Published Apr 12, 2004

Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow local users to bypass access controls and read unauthorized m…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1922

Published Apr 11, 2004

Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cau…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1923

Published Apr 11, 2004

Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-ad…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1924

Published Apr 11, 2004

Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1926

Published Apr 11, 2004

Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1927

Published Apr 11, 2004

Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1920

Published Apr 10, 2004

X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1918

Published Apr 9, 2004

RSniff 1.0 allows remote attackers to cause a denial of service (connection exhaustion) via a large number of connections with a command other than AUTHENTICATE, or without any da…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1919

Published Apr 9, 2004

The hash_strcmp function in hasch.c in Crackalaka 1.0.8 allows remote attackers to cause a denial of service (crash) via large malformed strings.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1915

Published Apr 8, 2004

Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1916

Published Apr 8, 2004

Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to pars…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,126-2,150 of 2,451 CVEsPage 86 of 99