Vulnerabilities (CVE)

Total 371924 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-2242 1 Phorum 1 Phorum 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter.
CVE-2004-2241 1 Phorum 1 Phorum 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this is inconsistent with the vendor's patch.
CVE-2004-2240 1 Phorum 1 Phorum 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php.
CVE-2004-2239 1 Inter7 1 Vpopmail \(vchkpw\) 2026-06-16 7.5 HIGH N/A
Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.
CVE-2004-2238 1 Inter7 1 Vpopmail \(vchkpw\) 2026-06-16 5.0 MEDIUM N/A
Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that, when compiled, became static format strings. Thus this is not a vulnerability
CVE-2004-2237 1 Moodle 1 Moodle 2026-06-16 10.0 HIGH N/A
Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."
CVE-2004-2236 1 Moodle 1 Moodle 2026-06-16 10.0 HIGH N/A
Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.
CVE-2004-2235 1 Moodle 1 Moodle 2026-06-16 10.0 HIGH N/A
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
CVE-2004-2234 1 Moodle 1 Moodle 2026-06-16 7.5 HIGH N/A
Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators.
CVE-2004-2233 1 Moodle 1 Moodle 2026-06-16 10.0 HIGH N/A
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
CVE-2004-2232 1 Moodle 1 Moodle 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.
CVE-2004-2231 1 Zero G 1 Installanywhere 2026-06-16 1.2 LOW N/A
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
CVE-2004-2230 1 Openbsd 1 Openbsd 2026-06-16 2.1 LOW N/A
Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.
CVE-2004-2229 1 Oracle 1 Database Server Lite 2026-06-16 4.6 MEDIUM N/A
Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges.
CVE-2004-2228 1 Mozilla 1 Firefox 2026-06-16 7.2 HIGH N/A
Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.
CVE-2004-2227 1 Mozilla 1 Firefox 2026-06-16 5.0 MEDIUM N/A
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
CVE-2004-2226 1 Mozilla 1 Thunderbird 2026-06-16 5.0 MEDIUM N/A
Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote attackers to determine valid e-mail addresses via an HTML e-mail that references a Cascading Style Sheets (CSS) document on the attacker's server.
CVE-2004-2225 1 Mozilla 1 Firefox 2026-06-16 5.0 MEDIUM N/A
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
CVE-2004-2224 1 Appfoundry 1 Message Foundry 2026-06-16 5.0 MEDIUM N/A
Appfoundry Message Foundry 2.75 .0003 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that contains MS-DOS device names such as com1.
CVE-2004-2223 1 Fsphpgallery 1 Fsphpgallery 2026-06-16 5.0 MEDIUM N/A
FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image.