Total
29929 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2004-1907 | 1 Kerio | 1 Personal Firewall | 2026-06-16 | 2.6 LOW | N/A |
| The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12%13". | |||||
| CVE-2004-1906 | 1 Mcafee | 1 Freescan | 2026-06-16 | 5.0 MEDIUM | N/A |
| Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in the ScanParam property of a COM object, which may trigger a buffer overflow. | |||||
| CVE-2004-1905 | 1 Panda | 1 Activescan | 2026-06-16 | 5.0 MEDIUM | N/A |
| ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSitesFile function. | |||||
| CVE-2004-1904 | 1 Panda | 1 Activescan | 2026-06-16 | 7.5 HIGH | N/A |
| Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Internacional property followed by a long string. | |||||
| CVE-2004-1903 | 1 Blaxxun | 1 Contact 3d | 2026-06-16 | 10.0 HIGH | N/A |
| Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an object tag. | |||||
| CVE-2004-1902 | 1 Citrix | 1 Metaframe Password Manager | 2026-06-16 | 2.1 LOW | N/A |
| The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. | |||||
| CVE-2004-1900 | 1 Pan Vision | 1 I.g.i-2 Covert Strike | 2026-06-16 | 7.5 HIGH | N/A |
| Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands. | |||||
| CVE-2004-1899 | 1 Tildeslash | 1 Monit | 2026-06-16 | 5.0 MEDIUM | N/A |
| The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes. | |||||
| CVE-2004-1898 | 1 Tildeslash | 1 Monit | 2026-06-16 | 10.0 HIGH | N/A |
| Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username. | |||||
| CVE-2004-1897 | 1 Tildeslash | 1 Monit | 2026-06-16 | 5.0 MEDIUM | N/A |
| Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes Monit to decrement a null pointer and perform an out-of-bounds read. | |||||
| CVE-2004-1896 | 1 Nullsoft | 1 Winamp | 2026-06-16 | 7.6 HIGH | N/A |
| Heap-based buffer overflow in in_mod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file. | |||||
| CVE-2004-1895 | 1 Suse | 1 Suse Linux | 2026-06-16 | 2.1 LOW | N/A |
| YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies. | |||||
| CVE-2004-1894 | 1 Pragma Ade | 1 Context | 2026-06-16 | 2.1 LOW | N/A |
| TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log. | |||||
| CVE-2004-1893 | 1 Macromedia | 2 Dreamweaver, Dreamweaver Ultradev | 2026-06-16 | 5.0 MEDIUM | N/A |
| Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp. | |||||
| CVE-2004-1892 | 1 Emule | 1 Emule | 2026-06-16 | 7.5 HIGH | N/A |
| Stack-based buffer overflow in DecodeBase16 function, as used in the (1) IRC module and (2) web server in eMule 0.42d, allows remote attackers to execute arbitrary code via a long string. | |||||
| CVE-2004-1891 | 1 Sgi | 1 Irix | 2026-06-16 | 5.0 MEDIUM | N/A |
| The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possibly preventing the actions of anonymous users from being logged. | |||||
| CVE-2004-1890 | 1 Sgi | 1 Irix | 2026-06-16 | 5.0 MEDIUM | N/A |
| Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode. | |||||
| CVE-2004-1889 | 1 Sgi | 1 Irix | 2026-06-16 | 5.0 MEDIUM | N/A |
| Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows. | |||||
| CVE-2004-1888 | 1 Aborior | 1 Encore Web Forum | 2026-06-16 | 7.5 HIGH | N/A |
| display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable. | |||||
| CVE-2004-1887 | 1 Ada | 1 Imgsvr | 2026-06-16 | 5.0 MEDIUM | N/A |
| Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null). | |||||
