LiveActive security incident?Get immediate response
CVE archive

February 2004

Browse CVE records published in February 2004, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 13 of 413 matching CVEs · Page 9 of 9.

Unknown · CVSS Not scored

CVE-2004-0084: Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowere...

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

Published Feb 14, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0132: Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers t...

Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.

Published Feb 14, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0005: Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly exe...

Multiple buffer overflows in Gaim 0.75 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) octal encoding in yahoo_decode that causes a null byte to be written beyond the buffer, (2) octal encoding in yahoo_decode that causes a pointer to reference memory beyond the terminating null byte, (3) a quoted printable string to the gaim_quotedp_decode MIME decoder that causes a null byte to be written beyond the buffer, and (4) quoted printable encoding in gaim_quotedp_decode that causes a pointer to reference memory beyond the terminating null byte.

Published Feb 3, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0039: Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firew...

Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.

Published Feb 11, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0002: The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of se...

The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.

Published Feb 3, 2004 · Updated Aug 8, 2024