Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

2,451 results · Page 38/50
5.0
CVE-2004-2578

phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which al

5.0
CVE-2004-2581

Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string."

5.0
CVE-2004-2582

Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote atta

5.0
CVE-2004-2586

Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remo

5.0
CVE-2004-2587

login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a

5.0
CVE-2004-2588

Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote a

5.0
CVE-2004-2589

Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length h

5.0
CVE-2004-2592

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (applica

5.0
CVE-2004-2594

Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows re

5.0
CVE-2004-2595

Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remo

5.0
CVE-2004-2596

Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaust

5.0
CVE-2004-2597

Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rul

5.0
CVE-2004-2598

Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state

5.0
CVE-2004-2600

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped

5.0
CVE-2004-2608

SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insuffi

5.0
CVE-2004-2617

Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the

5.0
CVE-2004-2620

The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers

5.0
CVE-2004-2628

Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to

5.0
CVE-2004-2636

TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.

5.0
CVE-2004-2640

Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files

5.0
CVE-2004-2641

Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cau

5.0
CVE-2004-2646

The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (unca

5.0
CVE-2004-2647

Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from t

5.0
CVE-2004-2654

The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cau

5.0
CVE-2004-2661

Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive i

5.0
CVE-2004-2662

Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) vi

5.0
CVE-2004-2664

John Lim ADOdb Library for PHP before 4.23 allows remote attackers to obtain sensitive information via direct requests t

5.0
CVE-2004-2666

Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_t

5.0
CVE-2004-2671

mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certai

5.0
CVE-2004-2680

mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 1638

5.0
CVE-2004-2705

Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain att

5.0
CVE-2004-2706

Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service

5.0
CVE-2004-2708

Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by

5.0
CVE-2004-2712

Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of servic

5.0
CVE-2004-2726

HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the Authorization header, which a

5.0
CVE-2004-2736

Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cooki

5.0
CVE-2004-2744

Unspecified vulnerability in Tincan Limited PHPlist before 2.8.12 has unknown impact and attack vectors, related to a "s

5.0
CVE-2004-2750

Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary f

4.9
CVE-2004-0138

The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted E

4.9
CVE-2004-2650

Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by trigger

4.9
CVE-2004-2660

Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.10 allows local users to cause a denial of service (memory c

4.9
CVE-2004-2665

Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.00, B.11.04,

4.8
CVE-2004-1865

Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users wi

4.7
CVE-2004-0244

Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allo

4.6
CVE-2003-0984

Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which cou

4.6
CVE-2003-0996

Unknown "System Security Vulnerability" in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers

4.6
CVE-2003-0998

Unknown "potential system security vulnerability" in Computer Associates (CA) Unicenter Remote Control 5.0 through 5.2,

4.6
CVE-2004-1124

Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and con

4.6
CVE-2004-0029

Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allow

4.6
CVE-2004-2134

Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the

Scan for 2004 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started