|
353001
|
6.4 |
MEDIUM
|
vignette
|
content_suite storyserver vignette
|
Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and direct…
|
NVD-CWE-Other
|
CVE-2003-0399
|
2016-10-18 11:33 |
2003-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353002
|
5.0 |
MEDIUM
|
vignette
|
content_suite storyserver vignette
|
Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string i…
|
NVD-CWE-Other
|
CVE-2003-0400
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353003
|
5.0 |
MEDIUM
|
vignette
|
content_suite storyserver vignette
|
Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template.
|
NVD-CWE-Other
|
CVE-2003-0401
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353004
|
5.0 |
MEDIUM
|
vignette
|
content_suite storyserver vignette
|
The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid username…
|
NVD-CWE-Other
|
CVE-2003-0402
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353005
|
7.5 |
HIGH
|
vignette
|
content_suite storyserver vignette
|
Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.
|
NVD-CWE-Other
|
CVE-2003-0403
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353006
|
4.3 |
MEDIUM
|
vignette
|
content_suite storyserver vignette
|
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demons…
|
NVD-CWE-Other
|
CVE-2003-0404
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353007
|
5.0 |
MEDIUM
|
vignette
|
content_suite storyserver vignette
|
Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is …
|
NVD-CWE-Other
|
CVE-2003-0405
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353008
|
7.2 |
HIGH
|
palmvnc
|
palmvnc
|
PalmVNC 1.40 and earlier stores passwords in plaintext in the PalmVNCDB, which is backed up to PCs that the Palm is synchronized with, which could allow attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2003-0406
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353009
|
10.0 |
HIGH
|
gnome
|
batalla_naval
|
Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.
|
NVD-CWE-Other
|
CVE-2003-0407
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353010
|
7.2 |
HIGH
|
the_uptimes_project
|
upclient
|
Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.
|
NVD-CWE-Other
|
CVE-2003-0408
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353011
|
10.0 |
HIGH
|
brs
|
webweaver
|
Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.
|
NVD-CWE-Other
|
CVE-2003-0409
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353012
|
10.0 |
HIGH
|
analogx
|
proxy
|
Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.
|
NVD-CWE-Other
|
CVE-2003-0410
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353013
|
5.0 |
MEDIUM
|
sun
|
one_application_server
|
Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.
|
NVD-CWE-Other
|
CVE-2003-0412
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353014
|
6.8 |
MEDIUM
|
sun
|
one_application_server
|
Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attack…
|
NVD-CWE-Other
|
CVE-2003-0413
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353015
|
7.2 |
HIGH
|
sun
|
one_application_server
|
The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password…
|
NVD-CWE-Other
|
CVE-2003-0414
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353016
|
5.0 |
MEDIUM
|
access-remote-pc.com
|
remote_pc_access
|
Remote PC Access Server 2.2 allows remote attackers to cause a denial of service (crash) by receiving packets from the server and sending them back to the server.
|
NVD-CWE-Other
|
CVE-2003-0415
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353017
|
6.8 |
MEDIUM
|
bandmin
|
bandmin
|
Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parame…
|
NVD-CWE-Other
|
CVE-2003-0416
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353018
|
5.0 |
MEDIUM
|
super-m
|
son_hserver
|
Directory traversal vulnerability in Son hServer 0.2 allows remote attackers to read arbitrary files via ".|." (modified dot-dot) sequences.
|
NVD-CWE-Other
|
CVE-2003-0417
|
2016-10-18 11:33 |
2003-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353019
|
5.0 |
MEDIUM
|
linux
|
linux_kernel
|
The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.
|
NVD-CWE-Other
|
CVE-2003-0418
|
2016-10-18 11:33 |
2003-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353020
|
7.5 |
HIGH
|
typespeed
|
typespeed
|
Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0435
|
2016-10-18 11:33 |
2003-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353021
|
3.6 |
LOW
|
aboleo.net
|
portmon
|
Portmon 1.7 and possibly earlier versions allows local users to read and write arbitrary files via the (1) -c (host file) or (2) -l (log file) command line options.
|
NVD-CWE-Other
|
CVE-2003-0448
|
2016-10-18 11:33 |
2003-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353022
|
4.6 |
MEDIUM
|
progress
|
database
|
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious lib…
|
NVD-CWE-Other
|
CVE-2003-0449
|
2016-10-18 11:33 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353023
|
7.5 |
HIGH
|
ximian
|
evolution
|
The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integ…
|
NVD-CWE-Other
|
CVE-2003-0296
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353024
|
7.5 |
HIGH
|
mozilla
|
mozilla
|
The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox s…
|
NVD-CWE-Other
|
CVE-2003-0298
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353025
|
7.5 |
HIGH
|
mutt stuart_parmenter
|
mutt balsa
|
The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values th…
|
NVD-CWE-Other
|
CVE-2003-0299
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353026
|
5.0 |
MEDIUM
|
microsoft mozilla mutt qualcomm stuart_parmenter sylpheed university_of_washington ximian
|
outlook_express mozilla mutt eudora balsa sylpheed_email_client pine evolution
|
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or inte…
|
NVD-CWE-Other
|
CVE-2003-0300
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353027
|
5.0 |
MEDIUM
|
microsoft
|
outlook_express
|
The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness…
|
NVD-CWE-Other
|
CVE-2003-0301
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353028
|
5.0 |
MEDIUM
|
qualcomm
|
eudora
|
The IMAP Client for Eudora 5.2.1 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer …
|
NVD-CWE-Other
|
CVE-2003-0302
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353029
|
5.0 |
MEDIUM
|
oneorzero
|
oneorzero_helpdesk
|
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
|
NVD-CWE-Other
|
CVE-2003-0303
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353030
|
10.0 |
HIGH
|
oneorzero
|
oneorzero_helpdesk
|
one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.
|
NVD-CWE-Other
|
CVE-2003-0304
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353031
|
7.5 |
HIGH
|
poster
|
poster
|
Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field.
|
NVD-CWE-Other
|
CVE-2003-0307
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353032
|
6.8 |
MEDIUM
|
ez
|
ez_publish
|
Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2003-0310
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353033
|
6.4 |
MEDIUM
|
snowblind.net
|
snowblind_web_server
|
Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.
|
NVD-CWE-Other
|
CVE-2003-0312
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353034
|
6.4 |
MEDIUM
|
snowblind.net
|
snowblind_web_server
|
Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request.
|
NVD-CWE-Other
|
CVE-2003-0313
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353035
|
6.4 |
MEDIUM
|
snowblind.net
|
snowblind_web_server
|
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence.
|
NVD-CWE-Other
|
CVE-2003-0314
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353036
|
7.5 |
HIGH
|
snowblind.net
|
snowblind_web_server
|
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.
|
NVD-CWE-Other
|
CVE-2003-0315
|
2016-10-18 11:32 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353037
|
4.3 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.
|
NVD-CWE-Other
|
CVE-2003-0318
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353038
|
7.5 |
HIGH
|
smartmax_software
|
mailmax
|
Buffer overflow in the IMAP server (IMAPMax) for SmartMax MailMax 5.0.10.8 and earlier allows remote authenticated users to execute arbitrary code via a long SELECT command.
|
NVD-CWE-Other
|
CVE-2003-0319
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353039
|
7.5 |
HIGH
|
andy_prevost
|
ttcms
|
header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that…
|
NVD-CWE-Other
|
CVE-2003-0320
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353040
|
7.5 |
HIGH
|
colten_edwards
|
bitchx
|
Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nic…
|
NVD-CWE-Other
|
CVE-2003-0321
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353041
|
7.5 |
HIGH
|
michael_sandrof
|
ircii
|
Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the…
|
NVD-CWE-Other
|
CVE-2003-0323
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353042
|
7.5 |
HIGH
|
epic
|
epic4
|
Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly h…
|
NVD-CWE-Other
|
CVE-2003-0324
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353043
|
4.6 |
MEDIUM
|
ambrosia_software
|
maelstrom
|
Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.
|
NVD-CWE-Other
|
CVE-2003-0325
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353044
|
4.6 |
MEDIUM
|
slocate
|
slocate
|
Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to mall…
|
NVD-CWE-Other
|
CVE-2003-0326
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353045
|
4.6 |
MEDIUM
|
aclogic
|
cesarftp
|
CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2003-0329
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353046
|
4.6 |
MEDIUM
|
ambrosia_software
|
maelstrom
|
Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.
|
NVD-CWE-Other
|
CVE-2003-0330
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353047
|
10.0 |
HIGH
|
ttcms
|
ttforum
|
SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.
|
NVD-CWE-Other
|
CVE-2003-0331
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353048
|
7.6 |
HIGH
|
working_resources_inc.
|
badblue
|
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers …
|
NVD-CWE-Other
|
CVE-2003-0332
|
2016-10-18 11:32 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353049
|
7.5 |
HIGH
|
slackware
|
slackware_linux
|
rc.M in Slackware 9.0 calls quotacheck with the -M option, which causes the filesystem to be remounted and possibly reset security-relevant mount flags such as nosuid, nodev, and noexec.
|
NVD-CWE-Other
|
CVE-2003-0335
|
2016-10-18 11:32 |
2003-05-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353050
|
5.0 |
MEDIUM
|
qualcomm
|
eudora
|
Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a spoofed "Attachment Converted:" string, which is not properly han…
|
NVD-CWE-Other
|
CVE-2003-0336
|
2016-10-18 11:32 |
2003-05-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|