Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

2004 Advisories Archive

Severity Date Check Point
Reference
Industry
Reference
Description

Updated
CPAI-2004-214 CVE-2004-0362 Update Protection against ISS ICQ Parsing Vulnerability

Updated
CPAI-2004-213 CVE-2003-1048 Update Protection against Internet Explorer Malformed GIF File Double Free (MS04-025)

Updated
CPAI-2004-212 CVE-2004-1043 Update Protection against Internet Explorer HTML Help Remote Code Execution (MS05-001)

Updated
CPAI-2004-211 CVE-2004-1361 Update Protection against Microsoft Winhlp32 Compressed Phrase Integer Overflow

Updated
CPAI-2004-210 CVE-2004-1049 Update Protection against Microsoft Windows LoadImage API Function Integer Overflow

Updated
CPAI-2004-209 CVE-2004-1153 Update Protection against Adobe Acrobat Reader eBook Format String

Updated
CPAI-2004-208 CVE-2004-0901 Update Protection against Microsoft WordPad Font Conversion Buffer Overflow

Updated
CPAI-2004-207 CVE-2004-1351 Update Protection against Sun Solaris in.rwhod Code Execution

Updated
CPAI-2004-206 CVE-2004-1541 Update Protection against VanDyke SecureCRT Arbitrary Configuration Folder Specification

Updated
CPAI-2004-205 CVE-2004-1155 Update Protection against Multiple Web Browsers Window Injection

Updated
CPAI-2004-204 CVE-2004-1164 Update Protection against Cisco CNS Network Registrar Denial of Service

Updated
CPAI-2004-203 CVE-2004-2501 Update Protection against MailEnable IMAP Service Buffer Overflow

Updated
CPAI-2004-202 CVE-2004-1135 Update Protection against Ipswitch WS_FTP Server Commands Buffer Overflow Denial of Service

Updated
CPAI-2004-201 TBD Update Protection against Internet Explorer Image Download Spoofing

Updated
CPAI-2004-200 CVE-2004-1029 Update Protection against Sun Java Plug-in Sandbox Security Bypass

Updated
CPAI-2004-199 CVE-2004-1119 Update Protection against Winamp IN_CDDA.dll Buffer Overflow

Updated
CPAI-2004-198 CVE-2004-1331 Update Protection against Internet Explorer execCommand File Type Spoofing

Updated
CPAI-2004-197 CVE-2004-1520 Update Protection against Ipswitch IMail IMAP Service DELETE Command Buffer Overflow

Updated
CPAI-2004-196 CVE-2004-0940 Update Protection against Apache mod_include Buffer Overflow

Updated
CPAI-2004-195 TBD Update Protection against Internet Explorer Status Bar URL Spoofing

Updated
CPAI-2004-194 CVE-2004-0918 Update Protection against Squid SNMP Parser ASN.1 Header Parsing Denial of Service

Updated
CPAI-2004-193 CVE-2005-0053 Update Protection against Internet Explorer Drag and Drop Code Execution

Updated
CPAI-2004-192 CVE-2004-0209 Update Protection against Microsoft Windows Graphics Rendering Engine Buffer Overflow (MS04-032)

Updated
CPAI-2004-191 CVE-2004-0846 Update Protection against Microsoft Excel Cell Length Buffer Overflow (MS04-033)

Updated
CPAI-2004-190 CVE-2004-0842 Update Protection against Internet Explorer CSS Memory Corruption

Updated
CPAI-2004-189 CVE-2003-0718 Update Protection against Microsoft IIS WebDAV XML Message Handler Denial of Service (MS04-030)

Updated
CPAI-2004-188 CVE-2004-0840 Update Protection against Microsoft SMTP Server DNS Handling (MS04-035)

Updated
CPAI-2004-187 CVE-2004-0847 Update Protection against Microsoft ASP.NET Resource Paths Canonicalization (MS05-004)

Updated
CPAI-2004-186 CVE-2004-0963 Update Protection against Microsoft Word Document Parsing Buffer Overflow (MS05-023)

Updated
CPAI-2004-185 CVE-2004-1481 Update Protection against RealNetworks RealPlayer Malformed RM File Heap Overflow

Updated
CPAI-2004-184 CVE-2004-0646 Update Protection against Macromedia JRun 4 mod_jrun Buffer Overflow Vulnerability

Updated
CPAI-2004-183 CVE-2004-0902 Update Protection against Mozilla Browser Non-ASCII Hostname Heap Overflow

Updated
CPAI-2004-182 CVE-2004-0928 Update Protection against Adobe JRun 4 Server File Disclosure

Updated
CPAI-2004-181 CVE-2004-1546 Update Protection against MDaemon SMTP and IMAP Command Buffer Overflow

Updated
CPAI-2004-180 CVE-2004-0369 Update Protection against Symantec Firewall Malformed Requests

Updated
CPAI-2004-179 CVE-2004-0959 Update Protection against PHP Arbitrary File Location Upload

Updated
CPAI-2004-178 CVE-2004-0799 Update Protection against Ipswitch WhatsUp Gold DOS Device HTTP Request Denial of Service

Updated
CPAI-2004-177 CVE-2004-0938 Update Protection against FreeRADIUS Illegal Attributes Denial of Service

Updated
CPAI-2004-176 CVE-2004-0786 Update Protection against Apache apr-util IPv6 URI Parsing

Updated
CPAI-2004-175 CVE-2004-0573 Update Protection against Microsoft WordPerfect 5.x Converter Buffer Overflow

Updated
CPAI-2004-174 CVE-2004-1364 Update Protection against Oracle Database Server MD2 package VALIDATE_GEOM procedure Buffer Overflow

Updated
CPAI-2004-173 CVE-2004-1364 Update Protection against Oracle Database Server String Conversion Function Buffer Overflow

Updated
CPAI-2004-172 CVE-2004-0637 Update Protection against Oracle Database Server ctxsys.driload Access Validation

Updated
CPAI-2004-171 CVE-2004-1371 Update Protection against Oracle 10g iSQLPLus Service Heap Overflow

Updated
CPAI-2004-170 CVE-2004-0798 Update Protection against Ipswitch WhatsUp Gold Web Server Buffer Overflow

Updated
CPAI-2004-169 CVE-2004-0788 Update Protection against CVS File Existence Information Disclosure

Updated
CPAI-2004-168 CVE-2004-0630 Update Protection against Adobe Acrobat Reader (Unix) Shell Metacharacter Code Execution

Updated
CPAI-2004-167 TBD Update Protection against Microsoft Windows Large Image Resize DoS

Updated
CPAI-2004-166 CVE-2004-0203 Update Protection against Microsoft Exchange OWA Cross-Site Scripting and Spoofing (MS04-026)

Updated
CPAI-2004-165 CVE-2004-0636 Update Protection against AOL Instant Messenger Away Message Buffer Overflow

Updated
CPAI-2004-164 CVE-2004-0597 Update Protection against libpng Transparency Chunk Length Buffer Overflow

Updated
CPAI-2004-163 CVE-2004-0722 Update Protection against Mozilla SOAPParameter Integer Overflow Vulnerability

Updated
CPAI-2004-162 CVE-2004-0728 Update Protection against Microsoft SMS Remote Control Service Denial of Service

Updated
CPAI-2004-161 CVE-2004-0763 Update Protection against Mozilla Firefox onunload SSL Certificate Spoofing

Updated
CPAI-2004-160 CVE-2004-0600 Update Protection against Samba SWAT HTTP Authentication Buffer Overflow

Updated
CPAI-2004-159 CVE-2004-0420 Update Protection against Microsoft Windows Shell Remote Code Execution (MS04-024)

Updated
CPAI-2004-158 CVE-2003-1041 Update Protection against Microsoft showHelp Vulnerability (MS04-023)

Updated
CPAI-2004-157 CVE-2004-0648 Update Protection against Mozilla Shell Protocol Validation

Updated
CPAI-2004-156 CVE-2004-0627 Update Protection against MySQL Malformed Password Authentication

Updated
CPAI-2004-155 CVE-2004-0668 Update Protection against IBM Lotus Domino Web Access Message Handling Denial of Service

Updated
CPAI-2004-154 CVE-2004-0719 Update Protection against Internet Explorer Frame Injection

Updated
CPAI-2004-153 CVE-2004-0417 Update Protection against CVS Max-dotdot Protocol Command Integer Overflow

Updated
CPAI-2004-152 CVE-2004-0416 Update Protection against CVS Argumentx Command Double Free

Updated
CPAI-2004-151 CVE-2004-0413 Update Protection against Subversion svn Protocol String Parsing

Updated
CPAI-2004-150 CVE-2004-0202 Update Protection against Microsoft DirectPlay Denial of Service

Updated
CPAI-2004-149 CVE-2004-0536 Update Protection against Tripwire Format String

Updated
CPAI-2004-148 CVE-2002-1770 Update Protection against Eudora URL Handling Buffer Overflow

Updated
CPAI-2004-147 CVE-2004-0411
CVE-2004-0473
Update Protection against Multiple Browsers Telnet URI Handler File Manipulation

Updated
CPAI-2004-146 CVE-2004-0234 Update Protection against F-Secure Anti-Virus LHA Processing Buffer Overflow

Updated
CPAI-2004-145 CVE-2004-0487 Update Protection against Symantec Norton AntiVirus 2004 ActiveX Denial of Service

Updated
CPAI-2004-144 CVE-2004-0396 Update Protection against CVS Entry Line Flag Remote Heap Overflow

Updated
CPAI-2004-143 CVE-2004-0444 Update Protection against Symantec Norton Firewall NBNS response Remote Heap Corruption

Updated
CPAI-2004-142 CVE-2004-0444 Update Protection against Norton Internet Security NBNS Response Processing Stack Overflow

Updated
CPAI-2004-141 CVE-2004-0199 Update Protection against Microsoft HSC URL Remote Code Execution (MS04-015)

Updated
CPAI-2004-140 CVE-2004-1992 Update Protection against Serv-U FTP Server LIST Parameter Buffer Overrun

Updated
CPAI-2004-139 CVE-2004-0426 Update Protection against RSync Arbitrary File Overwrite

Updated
CPAI-2004-138 CVE-2004-0431 Update Protection against Apple Quicktime Heap Overflow

Updated
CPAI-2004-137 CVE-2003-0907 Update Protection against Microsoft HSC URL RemoteCodeExecution (MS04-011)

Updated
CPAI-2004-136 CVE-2004-1908 Update Protection against Mcafee FreeScan Information Disclosure and Application Denial of Service

Updated
CPAI-2004-135 TBD Update Protection against Macromedia Flash Player LoadMovie Denial Of Service

Updated
CPAI-2004-134 TBD Update Protection against Internet Explorer MSWebDVD Class Null Pointer Assignment

Updated
CPAI-2004-133 TBD Update Protection against IBM Director Agent Denial of Service

Updated
CPAI-2004-132 CVE-2004-1896 Update Protection against Winamp XM File Heap Buffer Overflow

Updated
CPAI-2004-131 CVE-2004-0183 Update Protection against TCPDUMP ISAKMP Payload Handling DoS

Updated
CPAI-2004-130 CVE-2004-0176 Update Protection against Ethereal Netflow Dissector Buffer Overflow

Updated
CPAI-2004-129 CVE-2004-1868 Update Protection against Interactive Data eSignal Listener Buffer Overflow

Updated
CPAI-2004-128 CVE-2004-1856 Update Protection against HP WEB JETADMIN Denial of Service

Updated
CPAI-2004-127 CVE-2004-0368 Update Protection against XDMCP dtlogin Daemon Double Free

Updated
CPAI-2004-126 CVE-2004-0364 Update Protection against Norton Internet Security ActiveX Command Execution

Updated
CPAI-2004-125 CVE-2004-0363 Update Protection against Norton Internet Security 2004 symspam.dll Buffer Overflow

Updated
CPAI-2004-124 TBD Update Protection against InterWoven WorkDocs XSS Cross-Site Scripting

Updated
CPAI-2004-123 CVE-2004-0121 Update Protection against Microsoft Outlook 2002 Script Execution

Updated
CPAI-2004-122 CVE-2004-2383 Update Protection against Internet Explorer Cross Frame Scripting Restriction Bypass

Updated
CPAI-2004-121 CVE-2004-0330 Update Protection against Serv-U FTP Server Timezone MDTM Buffer Overflow

Updated
CPAI-2004-120 CVE-2004-0169 Update Protection against QuickTime-Darwin Denial of Service

Updated
CPAI-2004-119 TBD Update Protection against Microsoft Windows XP Explorer Heap Overflow

Updated
CPAI-2004-118 CVE-2004-0309 Update Protection against ZoneAlarm SMTP Buffer Overflow

Updated
CPAI-2004-117 CVE-2004-0164 Update Protection against KAME IKE Daemon (racoon) INITIAL_CONTACT Improper Handling

Updated
CPAI-2004-116 CVE-2004-0104 Update Protection against Metamail Format String And Buffer Overflow

Updated
CPAI-2004-115 CVE-2004-0297 Update Protection against IPSwitch IMAIL LDAP Overflow

Updated
CPAI-2004-114 CVE-2004-1815 Update Protection against Multiple Vendor SOAP Denial of Service

Updated
CPAI-2004-113 CVE-2003-0726 Update Protection against RealNetworks RealPlayer SMIL Cross-Site Scripting

Updated
CPAI-2004-112 CVE-2004-0258 Update Protection against RealNetworks RealPlayer Buffer Overflow

Updated
CPAI-2004-111 CVE-2003-0825 Update Protection against Microsoft WINS Denial Of Service

Updated
CPAI-2004-110 CVE-2004-1859 Update Protection against TrendMicro InterScan Viruswall Directory Traversal

Updated
CPAI-2004-109 CVE-2004-0095 Update Protection against McAfee ePolicy Orchestrator Agent HTTP POST Handling Flaw

Updated
CPAI-2004-108 CVE-2004-0420 Update Protection against Internet Explorer File Download Extension Spoofing (MS04-024)

Updated
CPAI-2004-107 CVE-2004-2111 Update Protection against Serv-U FTP Server Command Buffer Overflow

Updated
CPAI-2004-106 TBD Update Protection against InterNetNews NULL Path Denial of Service

Updated
CPAI-2004-105 CVE-2004-0045 Update Protection against InterNetNews Control Message Handling Buffer Overflow

Updated
CPAI-2004-104 CVE-2003-1200 Update Protection against MDaemon Raw Message Handler Buffer Overflow

Updated
CPAI-2004-103 CVE-2003-1025 Update Protection against Internet Explorer URL Spoofing

Updated
CPAI-2004-102 CVE-2003-0962 Update Protection against Rsync File Handling Integer Overflow

Updated
CPAI-2004-101 CVE-2003-0614 Update Protection against Gallery Search Engine Cross-Site Scripting

Updated
CPAI-2004-100 CVE-2002-0079 Update Protection against Microsoft IIS ISAPI Heap Overflow (MS02-018)
CPAI-2004-70   Spyware and Adware Protection
CPAI-2004-69   Command Injection Protection Preemptively Protects against Santy.C Worm

Updated
CPAI-2004-68 CAN-2004-1315 Santy.A & Santy.B Worms Protection

Updated
CPSA-2004-07   Security Best Practice: Preventing Command Injection Attacks Using Web Intelligence Command Injection Protection

Updated
CPAI-2004-67 CAN-2004-0568 Vulnerability in HyperTerminal Could Allow Code Execution (MS04-043)

Updated
CPAI-2004-66 CAN-2004-0901
CAN-2004-0571 
Vulnerability in WordPad Could Allow Code Execution (MS04-041)
CPAI-2004-65   Preemptive Protection against a New Variant of the Zafi Worm
CPAI-2004-64   Preemptive Protection against Abuse of ProFTPD SITE command to Modify System Information
CPAI-2004-63   Opera Input Validation Error in Processing MIME Content-Type/Content-Disposition Headers

Updated
CPAI-2004-62 CVE-2004-1134

Preemptive Protection against Multiple Vulnerabilities in Microsoft ISAPI extension W3Who

Updated
CPAI-2004-61 CAN-2004-1080 Microsoft Windows WINS Replication Packet Handling Vulnerability (MS04-045)
CPAI-2004-60   Proactive Protection against Multiple Mail Servers Exploits

Updated
CPAI-2004-59 CAN-2004-1029 Sun Java Plug-in Arbitrary Package Access Vulnerability

Updated
CPAI-2004-58   Preemptive Protection against WORM_SOBER.I (a new variant of the Sober worm)

Updated
CPAI-2004-57   UNIX RPC Interface Scanning Protection

Updated
CPSA-2004-06   0-day Protection against Remote Code Execution Using Malicious Code Protector
CPAI-2004-56   Preemptive Protection against Sun Java System Application Server HTTP TRACE Method Vulnerability

Updated
CPAI-2004-55 CAN-2004-0942 Apache HTTP Web Server Denial Of Service Vulnerability

Updated
CPAI-2004-54   MS-SQL Windows Authentication Enforcement

Updated
CPAI-2004-53 CAN-2004-1050 Internet Explorer IFRAME Tag Buffer Overflow (MS04-040)

Updated
CPAI-2004-52   RealNetworks RealPlayer Vulnerabilities

Updated
CPAI-2004-51 CVE-2004-0816 Preemptive Protection against Linux Kernel Firewall Logging Denial of Service

Updated
CPAI-2004-50   Preemptive Protection against WORM_BAGLE.AV/AT (a new variant of the Bagle worm)

Updated
CPAI-2004-49   A Vulnerability in Windows Server 2003 Mail Server Component Could Allow Remote Code Execution (MS04-035)
CPAI-2004-48   Microsoft Windows NetDDE Buffer Overflow Vulnerability (MS04-031)

Updated
CPAI-2004-47   Graphics Rendering Engine vulnerability (MS04-032) - CIFS Protection
CPAI-2004-46   Microsoft Windows Program Group Converter Vulnerability (MS04-037)
CPAI-2004-45   Preemptive Protection against Graphics Rendering Engine vulnerability (MS04-032)

Updated
CPAI-2004-44   Preemptive Protection against WebDAV XML Message Handler Denial of Service Vulnerability (MS04-030)
CPAI-2004-43   Microsoft SQL Server Denial of Service vulnerability

Updated
CPAI-2004-42 CAN-2004-0200
US-CERT: SA04-258A
Microsoft JPEG Processing Buffer Overflow vulnerability (MS04-028)

Updated
CPAI-2004-41   Pre-emptive Protection against Apache mod_dav LOCK Denial of Service Vulnerability

Updated
CPAI-2004-40   Serv-U FTP Server Denial of Service vulnerability
CPAI-2004-39   Preemptive Protection against WFTPD Pro Server Denial of Service vulnerability

Updated
CPSA-2004-05   Preemptive Protection: Blocking Files by Filename Extensions

Updated
CPSA-2004-04 CAN-2001-0776
CAN-2002-0997
CAN-2002-1349
CAN-2002-1539
CAN-2002-1580
CAN-2004-0140
CAN-2003-0167
CAN-2003-0296
CAN-2003-0299
CAN-2003-0300
CAN-2003-0319
CAN-2004-0224
Attacks on POP3 and IMAP4 Protocols

Updated
CPAI-2004-38   Netscape NSS Library Record Parsing Buffer Overflow
CPAI-2004-37   Cisco IOS Malformed OSPF Denial of Service vulnerability

Updated
CPAI-2004-36   Cross-Site Scripting vulnerability in Exchange Server 5.5 Outlook Web Access

Updated
CPAI-2004-35   Bagle.AG (a new variant of the Bagle worm)

Updated
CPAI-2004-34   W32/MyDoom.M worm (A new variant of MyDoom)

Updated
CPAI-2004-33   Samba SWAT HTTP Authentication Buffer Overflow vulnerability

Updated
CPSA-2004-03 BGP:
CVE-2001-0650
CAN-2004-0589
CAN-2004-0230
RIP:
CVE-1999-0111
OSPF:
CAN-2003-0100
Attacks on Dynamic Routing Protocols
CPAI-2004-32   PHP strip_tags Bypass vulnerability
CPAI-2004-31   Microsoft Outlook/Word Object Tag vulnerability
CPAI-2004-30 CAN-2003-1041
CAN-2004-0201
Microsoft HTML Help Vulnerability (MS04-023)

Updated
CPAI-2004-29   Windows Shell Remote Code Execution Vulnerability (MS04-024)
CPAI-2004-28   Microsoft IIS 4 Redirection Remote Code Execution Vulnerability (MS04-021)

Updated
CPAI-2004-27   Microsoft Windows Task Scheduler Remote Code Execution Vulnerability (MS04-022)

Updated
CPSA-2004-02 CAN-2004-0266
CAN-2004-0269
CAN-2004-0271
CAN-2004-0272
CAN-2004-0275
CAN-2004-0291
CAN-2004-0300
CAN-2004-0304
CAN-2004-0323
CAN-2004-0338
CAN-2004-0343
CAN-2004-0348
SQL Injection Attacks

Updated
CPAI-2004-22   Microsoft Internet Explorer 6 Arbitrary Code Execution

Updated
CPAI-2004-26   PHP-Nuke SQL Injection and XSS vulnerabilities

Updated
CPSA-2004-01 Microsoft Security
Microsoft Support
Microsoft Download_Ject Trojan

Updated
CPAI-2004-25 CAN-2002-1001
SOCKS-based Trojans

Updated
CPAI-2004-24 CAN-2004-0541 SQUID NTLM Authentication Buffer Overflow vulnerability

Updated
CPAI-2004-23 CAN-2004-0492 Apache 1.3 mod_proxy Buffer Overflow vulnerability

Updated
CPAI-2004-21   IRC-based worms

Updated
CPAI-2004-20

MS04-011
CAN-2003-0533
CPSA-2003-08
CPAI-2003-11

Microsoft LSASS Vulnerability / Sasser worm (MS04-011)

Updated
CPAI-2004-19   Microsoft SSL Library Remote Compromise Vulnerability

Updated
CPAI-2004-18   Microsoft Metafile Heap Overflow Vulnerability (MS04-011)

Updated
CPAI-2004-17   RST attack on RFC-based TCP stacks
CPAI-2004-16   The Rose IP Fragmentation Attack

Updated
CPAI-2004-15   IKE Aggressive Mode Vulnerabilities

Updated
CPAI-2004-14

CAN-2005-0362

Witty_worm

Updated
CPAI-2004-13   OpenSSL null-pointer assignment vulnerability
CPAI-2004-12   Ipswitch WS_FTP Server Stack Overflow Vulnerability

Updated
CPAI-2004-11   PhatBot/AgoBot Worm & Trojan

Updated
CPAI-2004-10   FreeBSD Memory Buffer Exhaustion DoS Vulnerability

Updated
CPAI-2004-09   WinZip MIME parsing remote code execution and buffer overflow

Updated
CPAI-2004-08   NetSky.C Worm

Updated
CPAI-2004-07 CAN-2003-0818
Microsoft ASN.1 Remote Code Execution (MS04-007)

Updated
CPAI-2004-06   NACHI_C worm

Updated
CPAI-2004-05   Soulseek – Peer to Peer
CPAI-2004-04   Serv-U FTP server Stack Overflow

Updated
CPAI-2004-03   Microsoft SQL Server Protections

Updated
CPAI-2004-02   Mimail.R/MyDoom

Updated
CPAI-2004-01   Bagle Mass Mailing Worm

Archives