|
352951
|
7.1 |
HIGH
|
splatt
|
splatt_forum
|
Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.
|
NVD-CWE-Other
|
CVE-2003-0590
|
2016-10-18 11:35 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352952
|
7.2 |
HIGH
|
sco
|
openserver
|
Unknown vulnerability in display of Merge before 5.3.23a in UnixWare 7.1.x allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2003-0597
|
2016-10-18 11:35 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352953
|
4.6 |
MEDIUM
|
hugo_rabson
|
mindi
|
mindi 0.58 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2003-0617
|
2016-10-18 11:35 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352954
|
4.6 |
MEDIUM
|
andries_brouwer
|
man
|
Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in…
|
NVD-CWE-Other
|
CVE-2003-0620
|
2016-10-18 11:35 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352955
|
10.0 |
HIGH
|
ehud_gavron
|
traceroute-nanog
|
traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is use…
|
NVD-CWE-Other
|
CVE-2003-0453
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352956
|
4.6 |
MEDIUM
|
imagemagick
|
libmagick_library
|
The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2003-0455
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352957
|
5.0 |
MEDIUM
|
linux
|
linux_kernel
|
Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC is enabled, or the ip_nat_ftp or ip_nat_irc modules…
|
NVD-CWE-Other
|
CVE-2003-0467
|
2016-10-18 11:34 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352958
|
7.5 |
HIGH
|
alt-n
|
webadmin
|
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.
|
NVD-CWE-Other
|
CVE-2003-0471
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352959
|
5.0 |
MEDIUM
|
ashley_brown
|
iweb_server
|
Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.
|
NVD-CWE-Other
|
CVE-2003-0474
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352960
|
5.0 |
MEDIUM
|
ashley_brown
|
iweb_server
|
Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability tha…
|
NVD-CWE-Other
|
CVE-2003-0475
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352961
|
5.0 |
MEDIUM
|
wzdftpd
|
wzdftpd
|
wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.
|
NVD-CWE-Other
|
CVE-2003-0477
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352962
|
10.0 |
HIGH
|
andromede daniel_moss hans_westerhof wenet bahamut
|
adromedeircd methane digatech ircd-ru ircd
|
Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ir…
|
NVD-CWE-Other
|
CVE-2003-0478
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352963
|
4.3 |
MEDIUM
|
affordable_web_space_design
|
affordable_web_space_design_webbbs
|
Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS allows remote attackers to insert arbitrary web script via the (1) Name, (2) Email, or (3) Message fields.
|
NVD-CWE-Other
|
CVE-2003-0479
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352964
|
3.7 |
LOW
|
vmware
|
workstation
|
VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."
|
NVD-CWE-Other
|
CVE-2003-0480
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352965
|
4.3 |
MEDIUM
|
gero_kohnert
|
tutos
|
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.
|
NVD-CWE-Other
|
CVE-2003-0481
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352966
|
7.5 |
HIGH
|
gero_kohnert
|
tutos
|
TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.
|
NVD-CWE-Other
|
CVE-2003-0482
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352967
|
6.8 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.
|
NVD-CWE-Other
|
CVE-2003-0484
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352968
|
4.6 |
MEDIUM
|
progress
|
4gl_compiler
|
Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.
|
NVD-CWE-Other
|
CVE-2003-0485
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352969
|
7.2 |
HIGH
|
dantz
|
retrospect_client
|
The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to…
|
NVD-CWE-Other
|
CVE-2003-0490
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352970
|
7.5 |
HIGH
|
mytutorials
|
tutorials
|
The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.
|
NVD-CWE-Other
|
CVE-2003-0491
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352971
|
10.0 |
HIGH
|
snitz_communications
|
snitz_forums_2000
|
Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.
|
NVD-CWE-Other
|
CVE-2003-0493
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352972
|
7.5 |
HIGH
|
microsoft
|
windows_2000
|
Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.
|
NVD-CWE-Other
|
CVE-2003-0503
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352973
|
4.3 |
MEDIUM
|
phpgroupware
|
phpgroupware
|
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.p…
|
NVD-CWE-Other
|
CVE-2003-0504
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352974
|
5.0 |
MEDIUM
|
microsoft
|
netmeeting
|
Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.
|
NVD-CWE-Other
|
CVE-2003-0505
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352975
|
5.0 |
MEDIUM
|
microsoft
|
netmeeting
|
Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
|
NVD-CWE-Other
|
CVE-2003-0506
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352976
|
7.5 |
HIGH
|
microsoft
|
windows_2000
|
Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 sear…
|
NVD-CWE-Other
|
CVE-2003-0507
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352977
|
7.5 |
HIGH
|
adobe
|
acrobat_reader
|
Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.
|
NVD-CWE-Other
|
CVE-2003-0508
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352978
|
7.5 |
HIGH
|
ezbounce
|
ezbounce
|
Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.
|
NVD-CWE-Other
|
CVE-2003-0510
|
2016-10-18 11:34 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352979
|
5.0 |
MEDIUM
|
cerulean_studios
|
trillian
|
Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.
|
NVD-CWE-Other
|
CVE-2003-0520
|
2016-10-18 11:34 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352980
|
6.8 |
MEDIUM
|
cpanel
|
cpanel
|
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not …
|
NVD-CWE-Other
|
CVE-2003-0521
|
2016-10-18 11:34 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352981
|
6.8 |
MEDIUM
|
cpanel
|
cpanel
|
This vulnerability is addressed in the following product release:
cPanel, cPanel, 7.0
|
NVD-CWE-Other
|
CVE-2003-0521
|
2016-10-18 11:34 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352982
|
10.0 |
HIGH
|
early_impact
|
productcart
|
Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privi…
|
NVD-CWE-Other
|
CVE-2003-0522
|
2016-10-18 11:34 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352983
|
6.8 |
MEDIUM
|
early_impact
|
productcart
|
Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.
|
NVD-CWE-Other
|
CVE-2003-0523
|
2016-10-18 11:34 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352984
|
6.2 |
MEDIUM
|
knoppix
|
knoppix
|
Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.
|
NVD-CWE-Other
|
CVE-2003-0524
|
2016-10-18 11:34 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352985
|
4.6 |
MEDIUM
|
icq_inc
|
icqlite
|
ICQLite 2003a creates the ICQ Lite directory with an ACE for "Full Control" privileges for Interactive Users, which allows local users to gain privileges as other users by replacing the executables w…
|
NVD-CWE-Other
|
CVE-2003-0365
|
2016-10-18 11:33 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352986
|
7.5 |
HIGH
|
prishtina_soft
|
prishtina_ftp
|
Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP banner.
|
NVD-CWE-Other
|
CVE-2003-0371
|
2016-10-18 11:33 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352987
|
4.6 |
MEDIUM
|
nessus
|
nessus
|
Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing…
|
CWE-189
数値処理の問題
|
CVE-2003-0372
|
2016-10-18 11:33 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352988
|
4.4 |
MEDIUM
|
nessus
|
nessus
|
Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long…
|
CWE-119
バッファエラー
|
CVE-2003-0373
|
2016-10-18 11:33 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352989
|
10.0 |
HIGH
|
nessus
|
nessus
|
Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar i…
|
NVD-CWE-noinfo
|
CVE-2003-0374
|
2016-10-18 11:33 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352990
|
5.0 |
MEDIUM
|
qualcomm
|
eudora
|
Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code via an Attachment Converted argument with a large n…
|
NVD-CWE-Other
|
CVE-2003-0376
|
2016-10-18 11:33 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352991
|
4.6 |
MEDIUM
|
michael_jennings debian
|
eterm debian_linux
|
Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.
|
NVD-CWE-Other
|
CVE-2003-0382
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352992
|
7.2 |
HIGH
|
debian
|
debian_linux
|
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.
|
NVD-CWE-Other
|
CVE-2003-0385
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352993
|
4.6 |
MEDIUM
|
andrew_morgan
|
linux_pam
|
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user …
|
NVD-CWE-Other
|
CVE-2003-0388
|
2016-10-18 11:33 |
2003-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352994
|
4.6 |
MEDIUM
|
james_theiler
|
opt
|
Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options th…
|
NVD-CWE-Other
|
CVE-2003-0390
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352995
|
7.5 |
HIGH
|
amax_information_technologies
|
magic_winmail_server
|
Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format s…
|
NVD-CWE-Other
|
CVE-2003-0391
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352996
|
6.4 |
MEDIUM
|
st
|
ftp_service
|
Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drive letter argument (e.g. E:).
|
NVD-CWE-Other
|
CVE-2003-0392
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352997
|
5.0 |
MEDIUM
|
privacyware
|
privatefirewall
|
Privacyware Privatefirewall 3.0 does not block certain incoming packets when in "Filter Internet Traffic" or Deny Internet Traffic" modes, which allows remote attackers to identify running services v…
|
NVD-CWE-Other
|
CVE-2003-0393
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352998
|
7.5 |
HIGH
|
blnews
|
blnews
|
objects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to malicious code on an attacker-controlled web site.
|
NVD-CWE-Other
|
CVE-2003-0394
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352999
|
7.5 |
HIGH
|
sharman_networks
|
kazaa
|
Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list…
|
NVD-CWE-Other
|
CVE-2003-0397
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353000
|
7.5 |
HIGH
|
vignette
|
content_suite storyserver vignette
|
Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is late…
|
NVD-CWE-Other
|
CVE-2003-0398
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|