Skip to main content

Year archive

CVEs published in 2004

Archive summary

2,451 CVEs published in 2004 — 229 Critical, 754 High, 1,265 Medium, 203 Low, 0 Unrated.

CVE-2004-1917

Published Apr 8, 2004

Format string vulnerability in test_func_func in LCDProc 0.4.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the str variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1357

Published Apr 7, 2004

The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1890

Published Apr 2, 2004

Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1875

Published Mar 30, 2004

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1876

Published Mar 30, 2004

The "%f" feature in the VirusEvent directive in Clam AntiVirus daemon (clamd) before 0.70 allows local users to execute arbitrary commands via shell metacharacters in a file name.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1877

Published Mar 30, 2004

The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attac…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1878

Published Mar 30, 2004

LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0170

Published Mar 29, 2004

Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0444

Published Mar 29, 2004

Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0601

Published Mar 29, 2004

Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0607

Published Mar 29, 2004

Buffer overflow in xconq 7.4.1 allows local users to become part of the "games" group via the (1) USER or (2) DISPLAY environment variables.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0612

Published Mar 29, 2004

Multiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to crafty.bin.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0796

Published Mar 29, 2004

Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0797

Published Mar 29, 2004

Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0828

Published Mar 29, 2004

Buffer overflow in freesweep in Debian GNU/Linux 3.0 allows local users to gain "games" group privileges when processing environment variables.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0993

Published Mar 29, 2004

mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1006

Published Mar 29, 2004

Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long comma…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1007

Published Mar 29, 2004

AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1008

Published Mar 29, 2004

Unknown vulnerability in Mac OS X 10.2.8 and 10.3.2 allows local users to bypass the screen saver login window and write a text clipping to the desktop or another application.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1009

Published Mar 29, 2004

Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or Ne…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1010

Published Mar 29, 2004

Unknown vulnerability in fs_usage in Mac OS X 10.2.8 and 10.3.2 and Mac OS X Server 10.2.8 and 10.3.2 allows local users to gain privileges via unknown attack vectors.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1011

Published Mar 29, 2004

Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the system is booting, which crashes…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1018

Published Mar 29, 2004

Format string vulnerability in enq command in AIX 4.3, 5.1, and 5.2 allows local users with rintq group privileges to gain privileges via unknown attack vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0113

Published Mar 29, 2004

Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL p…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 2,151-2,175 of 2,451 CVEsPage 87 of 99