Vulnerabilities (CVE)

Total 371113 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-0662 1 Powerportal 1 Powerportal 2026-06-16 5.0 MEDIUM N/A
PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message.
CVE-2004-0661 1 D-link 3 Di-604, Di-614\+, Di-624 2026-06-16 5.0 MEDIUM N/A
Integer signedness error in D-Link AirPlus DI-614+ running firmware 2.30 and earlier allows remote attackers to cause a denial of service (IP lease depletion) via a DHCP request with the LEASETIME option set to -1, which makes the DHCP lease valid for thirteen or more years.
CVE-2004-0660 1 Cutephp 1 Cutenews 2026-06-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter.
CVE-2004-0659 1 Mplayer 1 Mplayer 2026-06-16 10.0 HIGH N/A
Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name.
CVE-2004-0658 1 Linux 1 Linux Kernel 2026-06-16 7.2 HIGH N/A
Integer overflow in the hpsb_alloc_packet function (incorrectly reported as alloc_hpsb_packet) in IEEE 1394 (Firewire) driver 2.4 and 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via the functions (1) raw1394_write, (2) state_connected, (3) handle_remote_request, or (4) hpsb_make_writebpacket.
CVE-2004-0657 2 Hp, Ntp 2 Tru64 Unix, Ntp 2026-06-16 5.0 MEDIUM N/A
Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server's time.
CVE-2004-0656 1 Pureftpd 1 Pureftpd 2026-06-16 5.0 MEDIUM N/A
The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.
CVE-2004-0655 1 Esearch 1 Emerge Search Tool 2026-06-16 7.2 HIGH N/A
eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.
CVE-2004-0654 1 Sun 2 Solaris, Sunos 2026-06-16 2.1 LOW N/A
Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).
CVE-2004-0653 1 Sun 1 Solaris 2026-06-16 2.1 LOW N/A
Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.
CVE-2004-0652 1 Bea 1 Weblogic Server 2026-06-16 7.2 HIGH N/A
BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.
CVE-2004-0651 1 Sun 2 Jre, Sdk 2026-06-16 5.0 MEDIUM N/A
Unknown vulnerability in Sun Java Runtime Environment (JRE) 1.4.2 through 1.4.2_03 allows remote attackers to cause a denial of service (virtual machine hang).
CVE-2004-0650 1 Newatlanta 1 Servletexec 2026-06-16 10.0 HIGH N/A
UploadServlet in Cisco Collaboration Server (CCS) running ServletExec before 3.0E allows remote attackers to upload and execute arbitrary files via a direct call to the UploadServlet URL.
CVE-2004-0649 2 Gentoo, L2tpd 2 Linux, L2tpd 2026-06-16 10.0 HIGH N/A
Buffer overflow in write_packet in control.c for l2tpd may allow remote attackers to execute arbitrary code.
CVE-2004-0648 1 Mozilla 3 Firefox, Mozilla, Thunderbird 2026-06-16 10.0 HIGH N/A
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
CVE-2004-0647 1 Shorewall 1 Shorewall 2026-06-16 4.6 MEDIUM N/A
shorewall 1.4.10c and earlier, and 2.0.x before 2.0.3a, allows local users to overwrite arbitrary files via a symlink attack on the chains-$$ temporary file.
CVE-2004-0646 1 Macromedia 2 Coldfusion, Jrun 2026-06-16 10.0 HIGH N/A
Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
CVE-2004-0645 2 Abisource, Wvware 2 Community Abiword, Wvware 2026-06-16 10.0 HIGH N/A
Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 through 0.7.6 and 1.0.0 allows remote attackers to execute arbitrary code via a document with a long DateTime field.
CVE-2004-0644 1 Mit 1 Kerberos 5 2026-06-16 5.0 MEDIUM N/A
The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.
CVE-2004-0643 3 Debian, Mit, Redhat 5 Debian Linux, Kerberos 5, Enterprise Linux Desktop and 2 more 2026-06-16 4.6 MEDIUM N/A
Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.