Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,015 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 320 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2004-0771 | Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. | EXPLOIT ✓HIGH 10.0EPSS 18.8% | 23 November 2004 |
| CVE-2004-0636 | Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message. | EXPLOIT ×3 ✓HIGH 10.0EPSS 66.0% | 23 November 2004 |
| CVE-2004-0597 | Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of… | EXPLOIT ×3 ✓HIGH 10.0EPSS 82.5% | 23 November 2004 |
| CVE-2004-0354 | Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function… | EXPLOIT ✓HIGH 10.0EPSS 15.6% | 23 November 2004 |
| CVE-2004-0333 | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters. | EXPLOIT ✓HIGH 10.0EPSS 24.2% | 23 November 2004 |
| CVE-2004-0331 | Heap-based buffer overflow in Dell OpenManage Web Server 3.4.0 allows remote attackers to cause a denial of service (crash) via a HTTP POST with a long application variable. | MEDIUM 5.0EPSS 15.8% | 23 November 2004 |
| CVE-2004-0330 | Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command. | EXPLOIT ×6 ✓HIGH 10.0EPSS 85.5% | 23 November 2004 |
| CVE-2004-0326 | Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request. | EXPLOIT ×3 ✓HIGH 10.0EPSS 62.8% | 23 November 2004 |
| CVE-2004-0313 | Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name. | EXPLOIT ×5 ✓HIGH 10.0EPSS 63.6% | 23 November 2004 |
| CVE-2004-0297 | Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag… | EXPLOIT ×2 ✓HIGH 10.0EPSS 68.1% | 23 November 2004 |
| CVE-2004-0284 | Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters… | MEDIUM 5.0EPSS 16.8% | 23 November 2004 |
| CVE-2004-0277 | Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username. | EXPLOIT ✓HIGH 10.0EPSS 13.6% | 23 November 2004 |
| CVE-2004-0270 | libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail message with an invalid line length (e.g., a lowercase character), which causes an assert error in clamd that terminates the calling… | EXPLOIT ✓MEDIUM 5.0EPSS 10.4% | 23 November 2004 |
| CVE-2004-0203 | Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query. | MEDIUM 4.3EPSS 21.0% | 23 November 2004 |
| CVE-2004-0112 | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a… | MEDIUM 5.0EPSS 10.4% | 23 November 2004 |
| CVE-2004-1331 | The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command. | LOW 2.6EPSS 19.5% | 16 November 2004 |
| CVE-2004-1315 | viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special… | EXPLOIT ×4 ✓HIGH 7.5EPSS 72.1% | 12 November 2004 |
| CVE-2004-0885 | The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host… | HIGH 7.5EPSS 13.8% | 3 November 2004 |
| CVE-2004-0847 | The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path… | EXPLOIT ✓CRITICAL 9.8EPSS 71.5% | 3 November 2004 |
| CVE-2004-0846 | Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated. | HIGH 7.5EPSS 28.3% | 3 November 2004 |
| CVE-2004-0845 | Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user… | MEDIUM 6.4EPSS 31.0% | 3 November 2004 |
| CVE-2004-0844 | Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double… | MEDIUM 5.0EPSS 32.8% | 3 November 2004 |
| CVE-2004-0843 | Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing… | MEDIUM 5.0EPSS 33.8% | 3 November 2004 |
| CVE-2004-0840 | The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute… | HIGH 10.0EPSS 30.3% | 3 November 2004 |
| CVE-2004-0835 | MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct… | EXPLOIT ✓HIGH 7.5EPSS 22.4% | 3 November 2004 |
| CVE-2004-0832 | The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be… | MEDIUM 5.0EPSS 10.4% | 3 November 2004 |
| CVE-2004-0575 | Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an… | EXPLOIT ×2 ✓HIGH 10.0EPSS 60.3% | 3 November 2004 |
| CVE-2004-0574 | The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns,… | EXPLOIT ✓HIGH 10.0EPSS 64.4% | 3 November 2004 |
| CVE-2004-0572 | Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches… | HIGH 10.0EPSS 50.0% | 3 November 2004 |
| CVE-2004-0569 | The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values. | HIGH 7.5EPSS 19.4% | 3 November 2004 |
| CVE-2004-0552 | Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is… | EXPLOIT ✓HIGH 7.5EPSS 23.9% | 3 November 2004 |
| CVE-2004-0216 | Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when… | HIGH 10.0EPSS 48.7% | 3 November 2004 |
| CVE-2004-0214 | Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long… | EXPLOIT ✓HIGH 10.0EPSS 47.0% | 3 November 2004 |
| CVE-2004-0209 | Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats… | EXPLOIT ✓HIGH 10.0EPSS 57.4% | 3 November 2004 |
| CVE-2004-0206 | Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or… | EXPLOIT ×2 ✓HIGH 7.5EPSS 74.7% | 3 November 2004 |
| CVE-2003-0718 | The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements… | EXPLOIT ✓MEDIUM 5.0EPSS 87.9% | 3 November 2004 |
| CVE-2004-1627 | Buffer overflow in Ability Server 2.25, 2.32, 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long APPE command. | EXPLOIT ✓HIGH 7.5EPSS 14.5% | 22 October 2004 |
| CVE-2004-1626 | Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 67.4% | 22 October 2004 |
| CVE-2004-1623 | The WAV file property handler in Windows XP SP1 allows remote attackers to cause a denial of service (infinite loop in Explorer) via a WAV file with an invalid file header whose fmt chunk length is set to 0xFFFFFFFF. | EXPLOIT ✓MEDIUM 5.0EPSS 18.6% | 22 October 2004 |
| CVE-2004-0798 | Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter. | EXPLOIT ×2 ✓HIGH 7.5EPSS 62.6% | 20 October 2004 |
| CVE-2004-0786 | The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool. | MEDIUM 5.0EPSS 24.1% | 20 October 2004 |
| CVE-2004-0777 | Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code. | EXPLOIT ✓HIGH 7.5EPSS 10.9% | 20 October 2004 |
| CVE-2004-0751 | The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault). | EXPLOIT ✓MEDIUM 5.0EPSS 72.3% | 20 October 2004 |
| CVE-2004-0748 | mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop. | MEDIUM 5.0EPSS 24.7% | 20 October 2004 |
| CVE-2004-1638 | Buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long (1) EHLO and possibly (2) HELO command. | EXPLOIT ×3 ✓HIGH 7.5EPSS 62.8% | 16 October 2004 |
| CVE-2004-1602 | ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response. | EXPLOIT ✓MEDIUM 5.0EPSS 30.7% | 15 October 2004 |
| CVE-2004-1595 | Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field. | EXPLOIT ×2 ✓HIGH 7.5EPSS 59.3% | 13 October 2004 |
| CVE-2004-0691 | Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code. | EXPLOIT ✓HIGH 7.5EPSS 14.7% | 28 September 2004 |
| CVE-2004-0573 | Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website. | HIGH 7.5EPSS 42.3% | 28 September 2004 |
| CVE-2004-0558 | The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port. | EXPLOIT ✓MEDIUM 5.0EPSS 26.8% | 28 September 2004 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.