LiveActive security incident?Get immediate response
CVE archive

2004 CVE Archive

Browse CVE records published in 2004 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2644 matching CVEs · Page 6 of 53.

Unknown · CVSS Not scored

CVE-2004-2571: Multiple buffer overflows in EnderUNIX isoqlog 2.1.1 allow remote attackers to execute arbitrary code via t...

Multiple buffer overflows in EnderUNIX isoqlog 2.1.1 allow remote attackers to execute arbitrary code via the (1) parseQmailFromBytesLine, (2) parseQmailToRemoteLine, (3) parseQmailToLocalLine, (4) parseSendmailFromBytesLine, (5) parseSendmailToLine, (6) parseEximFromBytesLine, and (7) parseEximToLine functions in Parser.c; allow local users to execute arbitrary code via the (8) lowercase and (9) check_syslog_date functions in Parser.c, and (10) unspecified functions in Dir.c; and allow unspecified attackers to execute arbitrary code via the (11) loadconfig and (12) removespaces functions in loadconfig.c, the (13) loadLang function in LangCfg.c, and (14) unspecified functions in Html.c.

Published Nov 22, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2597: Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based acces...

Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the client's IP address.

Published Nov 29, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2595: Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products...

Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a download command with a full pathname for a directory in the argument, which causes the server to crash when it cannot read data.

Published Nov 29, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2572: AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) inval...

AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails, due to improper processing of the $keyword variable.

Published Nov 22, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2566: Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum...

Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.

Published Nov 22, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2548: Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail all...

Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).

Published Nov 21, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2565: Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other ver...

Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a "..\" (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp.

Published Nov 22, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2555: Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR...

Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key.

Published Nov 21, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2551: Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary...

Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands via (1) the sys_comment_id parameter in editcommentenduser.asp, (2) the sys_suspend_id parameter in editsuspensionuser.asp, (3) the table parameter in export_data.asp, (4) the sys_analgroup parameter in manageanalgrouppreference.asp, (5) the sys_asset_id parameter in quickinfoassetrequests.asp, (6) the sys_eusername parameter in quickinfoenduserrequests.asp, and the sys_request_id parameter in (7) requestauditlog.asp, (8) requestcommentsenduser.asp, (9) selectrequestapplytemplate.asp, and (10) selectrequestlink.asp, resulting in an ability to create a new HelpBox user account and read, modify, or delete data from the backend database.

Published Nov 21, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2543: Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of servi...

Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy, or (3) invalid MIME messages to the mail filter. NOTE: this might not be a vulnerability because the embedded monitoring sub-system automatically restarts after the failure.

Published Nov 20, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2552: Buffer overflow in XBoard 4.2.7 and earlier might allow local users to execute arbitrary code via a long -i...

Buffer overflow in XBoard 4.2.7 and earlier might allow local users to execute arbitrary code via a long -icshost command line argument. NOTE: since the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.

Published Nov 21, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2004-2515: Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, mi...

Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already available to the attackers, so this might not be a vulnerability.

Published Oct 25, 2005 · Updated Aug 8, 2024