LiveActive security incident?Get immediate response
CVE archive

October 2004

Browse CVE records published in October 2004, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 191 matching CVEs · Page 3 of 4.

Unknown · CVSS Not scored

CVE-2004-0990: Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote a...

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

Published Oct 28, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0989: Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow rem...

Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.

Published Oct 28, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0963: Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attac...

Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.

Published Oct 20, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-0985: Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated...

Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to write to a .hta file that is interpreted in the Local Zone by HTML Help.

Published Oct 26, 2004 · Updated Aug 8, 2024