Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29929 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-0269 1 Francisco Burzi 1 Php-nuke 2026-06-16 6.4 MEDIUM N/A
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.
CVE-2004-0268 1 Evolutionx 1 Evolutionx 2026-06-16 5.0 MEDIUM N/A
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server.
CVE-2004-0267 1 Broadcom 1 Inoculateit 2026-06-16 2.1 LOW N/A
The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.
CVE-2004-0266 1 Francisco Burzi 1 Php-nuke 2026-06-16 5.0 MEDIUM N/A
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter.
CVE-2004-0265 1 Francisco Burzi 1 Php-nuke 2026-06-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.
CVE-2004-0264 2 Jim Rees, Shaun2k2 2 Jim Rees Httpd, Palmhttpd 2026-06-16 5.0 MEDIUM N/A
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.
CVE-2004-0263 2 Apache, Ibm 2 Http Server, Http Server 2026-06-16 5.0 MEDIUM N/A
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
CVE-2004-0262 1 The Palace 1 The Palace Client 2026-06-16 10.0 HIGH N/A
Stack-based buffer overflow in The Palace 3.5 and earlier client allows remote attackers to execute arbitrary code via a link to a palace:// url followed by a long server address string.
CVE-2004-0261 1 Openjournal 1 Openjournal 2026-06-16 10.0 HIGH N/A
oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel via a 0 in the uid parameter.
CVE-2004-0260 1 Cactusoft 1 Cactushop Lite 2026-06-16 5.0 MEDIUM N/A
The AddToMailingList function in CactuSoft CactuShop 5.0 Lite contains a backdoor that allows remote attackers to delete arbitrary files via an email address that starts with |||.
CVE-2004-0259 1 Joe Lumbroso Acks 1 Formmail.php 2026-06-16 9.3 HIGH N/A
The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.
CVE-2004-0258 1 Realnetworks 4 Realone Desktop Manager, Realone Enterprise Desktop, Realone Player and 1 more 2026-06-16 7.6 HIGH N/A
Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files.
CVE-2004-0257 2 Netbsd, Openbsd 2 Netbsd, Openbsd 2026-06-16 5.0 MEDIUM N/A
OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.
CVE-2004-0256 1 Gnu 1 Libtool 2026-06-16 2.1 LOW N/A
GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.
CVE-2004-0255 1 Xlight Ftp Server 1 Xlight Ftp Server 2026-06-16 5.0 MEDIUM N/A
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.
CVE-2004-0254 1 Crosscom Olicom 1 Discuz 2026-06-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag.
CVE-2004-0253 1 Ibm 1 Cloudscape 2026-06-16 10.0 HIGH N/A
IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.
CVE-2004-0252 1 Typsoft 1 Typsoft Ftp Server 2026-06-16 5.0 MEDIUM N/A
TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.
CVE-2004-0251 1 Rxgoogle.cgi 1 Rxgoogle.cgi 2026-06-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other users via the query parameter.
CVE-2004-0250 1 Photopost 1 Photopost Php Pro 2026-06-16 10.0 HIGH N/A
SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.