Vulnerabilities (CVE)

Total 371947 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2286 2 Activestate, Larry Wall 2 Activeperl, Perl 2026-06-16 7.5 HIGH N/A
Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow.
CVE-2004-2284 1 Open Webmail 1 Open Webmail 2026-06-16 10.0 HIGH N/A
The read_list_from_file function in vacation.pl for OpenWebmail before 2.32 20040629 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename argument.
CVE-2004-2283 1 Daniel Barron 1 Dansguardian 2026-06-16 5.0 MEDIUM N/A
Unknown vulnerability in DansGuardian before 2.6.1-13 allows remote attackers to bypass URL filters via a crafted request that causes a page to be added to the clean page cache.
CVE-2004-2282 1 Daniel Barron 1 Dansguardian 2026-06-16 5.0 MEDIUM N/A
DansGuardian before 2.7.7-2 allows remote attackers to bypass URL filters via a ".." in the request.
CVE-2004-2281 1 Ibm 1 Lotus Notes 2026-06-16 10.0 HIGH N/A
Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3.
CVE-2004-2280 1 Ibm 1 Lotus Notes 2026-06-16 5.0 MEDIUM N/A
Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN.
CVE-2004-2279 1 Invision Power Services 1 Invision Power Board 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.
CVE-2004-2278 1 Chaogic Systems 1 Vhost 2026-06-16 4.3 MEDIUM N/A
Unknown cross-site scripting (XSS) vulnerability in the web GUI in vHost before 3.10r1 has unknown impact and attack vectors.
CVE-2004-2277 1 Agsm 1 Agsm 2026-06-16 5.0 MEDIUM N/A
Buffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server response.
CVE-2004-2276 1 F-secure 1 F-secure Anti-virus 2026-06-16 2.1 LOW N/A
F-Secure Anti-Virus 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlier for Linux does not properly detect certain viruses in a PKZip archive, which allows viruses such as Sober.D and Sober.G to bypass initial detection.
CVE-2004-2275 1 I-mall Commerce 1 I-mall.cgi 2026-06-16 10.0 HIGH N/A
i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter.
CVE-2004-2274 1 W3c 1 Jigsaw 2026-06-16 6.4 MEDIUM N/A
Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.
CVE-2004-2273 1 Evan Sims 1 Effingerd 2026-06-16 5.0 MEDIUM N/A
efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error.
CVE-2004-2272 1 Evan Sims 1 Effingerd 2026-06-16 5.0 MEDIUM N/A
Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command.
CVE-2004-2271 1 Minishare 1 Minimal Http Server 2026-06-16 7.5 HIGH N/A
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
CVE-2004-2270 1 Ibm 1 Parallel Environment 2026-06-16 7.2 HIGH N/A
Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.
CVE-2004-2269 1 Matt Shelton 1 Pads 2026-06-16 7.2 HIGH N/A
Stack-based buffer overflow in pads.c in Passive Asset Detection System (Pads) might allow local users to execute arbitrary code via a long report file name argument. NOTE: since Pads is not normally installed setuid, this may not be a vulnerability.
CVE-2004-2268 1 Pimentech 1 Pimengest2 2026-06-16 5.0 MEDIUM N/A
PimenGest2 before 1.1.1 allows remote attackers to obtain the database password via debug information in rowLatex.inc.php.
CVE-2004-2267 1 Ansel 1 Ansel 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Ansel 2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via the album name.
CVE-2004-2266 1 Ansel 1 Ansel 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in Ansel 2.1 and earlier allows remote attackers to modify SQL statements via the image parameter.