Skip to main content

Year archive

CVEs published in 2004

Archive summary

2,451 CVEs published in 2004 — 229 Critical, 754 High, 1,265 Medium, 203 Low, 0 Unrated.

CVE-2004-0126

Published Mar 29, 2004

The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local u…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0158

Published Mar 29, 2004

Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c,…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0160

Published Mar 29, 2004

Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0194

Published Mar 29, 2004

Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to execute arbitrary code via a PDF document with XML Forms Data…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1870

Published Mar 29, 2004

Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1871

Published Mar 29, 2004

Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1872

Published Mar 29, 2004

Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web script or HTML via the @import URL function in a CSS style…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1874

Published Mar 29, 2004

Multiple cross-site scripting (XSS) vulnerabilities in (1) deliver.asp and (2) billing.asp in A-CART Pro and A-CART 2.0 allow remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1862

Published Mar 26, 2004

Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xm…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1864

Published Mar 26, 2004

SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1865

Published Mar 26, 2004

Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or H…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1866

Published Mar 26, 2004

nstxd in Nstx 1.1 beta3 and earlier allows remote attackers to cause a denial of service (crash) via a large packet, which triggers a null dereference.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1861

Published Mar 25, 2004

Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1868

Published Mar 25, 2004

Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1849

Published Mar 24, 2004

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to dodelautores.html…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1851

Published Mar 24, 2004

Dameware Mini Remote Control 4.1.0.0 uses insufficiently random data to create the encryption key, which makes it easier for remote attackers to obtain sensitive information via b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1854

Published Mar 24, 2004

Buffer overflow in the logging function in Picophone 1.63 and earlier allows remote attackers to execute arbitrary code via a large packet.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1856

Published Mar 24, 2004

devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1857

Published Mar 24, 2004

Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude par…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1859

Published Mar 24, 2004

Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2037

Published Mar 24, 2004

Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1850

Published Mar 23, 2004

The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1852

Published Mar 23, 2004

DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1855

Published Mar 23, 2004

Dark Age of Camelot before 1.68 live patch does not sign the RSA public key, which could allow remote malicious servers to gain sensitive information via a man-in-the-middle attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,176-2,200 of 2,451 CVEsPage 88 of 99