LiveActive security incident?Get immediate response
CVE archive

February 2004

Browse CVE records published in February 2004, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 413 matching CVEs · Page 6 of 9.

Unknown · CVSS Not scored

CVE-2004-1527: Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribut...

Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions.

Published Feb 19, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-1553: SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via...

SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a processlogin action to album.asp, as reachable from the login action.

Published Feb 20, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-1503: Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other...

Integer overflow in the InitialDirContext in Java Runtime Environment (JRE) 1.4.2, 1.5.0 and possibly other versions allows remote attackers to cause a denial of service (Java exception and failed DNS requests) via a large number of DNS requests, which causes the xid variable to wrap around and become negative.

Published Feb 19, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-1473: Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Sec...

Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a source port of UDP 53.

Published Feb 13, 2005 · Updated Aug 8, 2024