LiveActive security incident?Get immediate response
CVE archive

January 2004

Browse CVE records published in January 2004, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 150 matching CVEs · Page 3 of 3.

Unknown · CVSS Not scored

CVE-2004-0592: The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI...

The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type, a similar flaw to CVE-2004-0626.

Published Jan 23, 2006 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0091: NOTE: this issue has been disputed by the vendor.

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.

Published Jan 22, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0067: Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inj...

Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, (3) individual.php, (4) login.php, (5) relationship.php, (6) source.php, (7) imageview.php, (8) calendar.php, (9) gedrecord.php, (10) login.php, and (11) gdbi_interface.php. NOTE: some aspects of vector 10 were later reported to affect 4.1.

Published Jan 15, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0056: Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications M...

Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

Published Jan 15, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0057: The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows...

The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.

Published Jan 15, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0006: Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers t...

Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.

Published Jan 29, 2004 · Updated Aug 8, 2024