LiveActive security incident?Get immediate response
CVE archive

August 2004

Browse CVE records published in August 2004, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 253 matching CVEs · Page 5 of 6.

Unknown · CVSS Not scored

CVE-2004-2300: Buffer overflow in snmpd in ucd-snmp 4.2.6 and earlier, when installed setuid root, allows local users to e...

Buffer overflow in snmpd in ucd-snmp 4.2.6 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -p command line argument. NOTE: it is not clear whether there are any standard configurations in which snmpd is installed setuid or setgid. If not, then this issue should not be included in CVE.

Published Aug 5, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0771: Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary co...

Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.

Published Aug 5, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0630: The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versi...

The uudecoding feature in Adobe Acrobat Reader 5.0.5 and 5.0.6 for Unix and Linux, and possibly other versions including those before 5.0.9, allows remote attackers to execute arbitrary code via shell metacharacters ("`" or backtick) in the filename of the PDF file that is provided to the uudecode command.

Published Aug 14, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0597: Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers...

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

Published Aug 5, 2004 · Updated Aug 8, 2024