|
356601
|
7.5 |
HIGH
|
mpg123 suse
|
mpg123 suse_linux
|
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
|
NVD-CWE-Other
|
CVE-2004-0991
|
2008-09-11 04:28 |
2005-01-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356602
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.
|
NVD-CWE-Other
|
CVE-2004-0086
|
2008-09-11 04:25 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356603
|
2.1 |
LOW
|
apple
|
mac_os_x
|
The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.
|
NVD-CWE-Other
|
CVE-2004-0088
|
2008-09-11 04:25 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356604
|
10.0 |
HIGH
|
apple
|
mac_os_x
|
Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.
|
NVD-CWE-Other
|
CVE-2004-0092
|
2008-09-11 04:25 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356605
|
10.0 |
HIGH
|
freebsd
|
freebsd
|
The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets …
|
NVD-CWE-Other
|
CVE-2004-0002
|
2008-09-11 04:24 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356606
|
5.0 |
MEDIUM
|
beasts
|
vsftpd
|
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
|
NVD-CWE-Other
|
CVE-2004-0042
|
2008-09-11 04:24 |
2004-02-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356607
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.
|
NVD-CWE-Other
|
CVE-2003-1220
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356608
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communi…
|
NVD-CWE-Other
|
CVE-2003-1221
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356609
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext …
|
NVD-CWE-Other
|
CVE-2003-1222
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356610
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as d…
|
NVD-CWE-Other
|
CVE-2003-1223
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356611
|
2.1 |
LOW
|
bea
|
weblogic_server
|
Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by…
|
NVD-CWE-Other
|
CVE-2003-1224
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356612
|
2.1 |
LOW
|
bea
|
weblogic_server
|
The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.
|
NVD-CWE-Other
|
CVE-2003-1225
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356613
|
2.1 |
LOW
|
bea
|
weblogic_server
|
BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to…
|
NVD-CWE-Other
|
CVE-2003-1226
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356614
|
7.5 |
HIGH
|
cisco
|
80-7111-01_for_the_unity-svrx255-1a 80-7112-01_for_the_unity-svrx255-2a
|
Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bu…
|
NVD-CWE-Other
|
CVE-2003-0983
|
2008-09-11 04:21 |
2004-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356615
|
5.0 |
MEDIUM
|
cisco
|
catalyst_6500 catalyst_6500_ws-svc-nam-1 catalyst_6500_ws-svc-nam-2 catalyst_6500_ws-x6380-nam catalyst_7600_ws-svc-nam-1 catalyst_7600_ws-svc-nam-2 catalyst_7600_ws-x6380-nam fi…
|
Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth reque…
|
NVD-CWE-Other
|
CVE-2003-1001
|
2008-09-11 04:21 |
2004-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356616
|
5.0 |
MEDIUM
|
cisco
|
catalyst_6500 catalyst_6500_ws-svc-nam-1 catalyst_6500_ws-svc-nam-2 catalyst_6500_ws-x6380-nam catalyst_7600_ws-svc-nam-1 catalyst_7600_ws-svc-nam-2 catalyst_7600_ws-x6380-nam fi…
|
Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is …
|
NVD-CWE-Other
|
CVE-2003-1002
|
2008-09-11 04:21 |
2004-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356617
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.
|
NVD-CWE-Other
|
CVE-2003-1005
|
2008-09-11 04:21 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356618
|
2.1 |
LOW
|
linux
|
linux_kernel
|
Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).
|
NVD-CWE-Other
|
CVE-2003-0643
|
2008-09-11 04:20 |
2003-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356619
|
7.5 |
HIGH
|
trend_micro
|
damage_cleanup_server housecall
|
Multiple buffer overflows in ActiveX controls used by Trend Micro HouseCall 5.5 and 5.7, and Damage Cleanup Server 1.0, allow remote attackers to execute arbitrary code via long parameter strings.
|
NVD-CWE-Other
|
CVE-2003-0646
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356620
|
7.5 |
HIGH
|
cisco
|
ios
|
Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.
|
NVD-CWE-Other
|
CVE-2003-0647
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356621
|
7.2 |
HIGH
|
xpcd
|
xpcd
|
Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2003-0649
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356622
|
5.0 |
MEDIUM
|
netbsd
|
netbsd
|
The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote a…
|
NVD-CWE-Other
|
CVE-2003-0653
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356623
|
7.5 |
HIGH
|
autorespond
|
autorespond
|
Buffer overflow in autorespond may allow remote attackers to execute arbitrary code as the autorespond user via qmail.
|
NVD-CWE-Other
|
CVE-2003-0654
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356624
|
2.1 |
LOW
|
sustainable_softworks
|
ipnetmonitorx ipnetsentryx
|
Sustworks IPNetSentryX and IPNetMonitorX allow local users to sniff network packets via the setuid helper applications (1) RunTCPDump, which calls tcpdump, and (2) RunTCPFlow, which calls tcpflow.
|
NVD-CWE-Other
|
CVE-2003-0670
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356625
|
7.2 |
HIGH
|
jeremy_elson
|
tcpflow
|
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMo…
|
NVD-CWE-Other
|
CVE-2003-0671
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356626
|
7.5 |
HIGH
|
leon_j_breedt
|
pam-pgsql
|
Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled whe…
|
NVD-CWE-Other
|
CVE-2003-0672
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356627
|
5.0 |
MEDIUM
|
cisco
|
webns
|
Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM…
|
NVD-CWE-Other
|
CVE-2003-0677
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356628
|
2.1 |
LOW
|
sgi
|
irix
|
Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allows local users to truncate or overwrite certain files.
|
NVD-CWE-Other
|
CVE-2003-0679
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356629
|
7.5 |
HIGH
|
sgi
|
irix
|
Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.
|
NVD-CWE-Other
|
CVE-2003-0680
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356630
|
7.5 |
HIGH
|
redhat
|
enterprise_linux
|
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number…
|
NVD-CWE-Other
|
CVE-2003-0689
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356631
|
7.2 |
HIGH
|
ibm
|
aix
|
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
|
NVD-CWE-Other
|
CVE-2003-0697
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356632
|
7.5 |
HIGH
|
nicolas_boullis
|
mah-jong
|
Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0705
|
2008-09-11 04:20 |
2003-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356633
|
5.0 |
MEDIUM
|
nicolas_boullis
|
mah-jong
|
Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).
|
NVD-CWE-Other
|
CVE-2003-0706
|
2008-09-11 04:20 |
2003-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356634
|
7.5 |
HIGH
|
whois
|
whois
|
Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.
|
NVD-CWE-Other
|
CVE-2003-0709
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356635
|
7.5 |
HIGH
|
gkrellm
|
gkrellm
|
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0723
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356636
|
10.0 |
HIGH
|
cisco
|
resource_manager resource_manager_essentials ciscoworks_common_management_foundation ciscoworks_cd1
|
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly in…
|
NVD-CWE-Other
|
CVE-2003-0731
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356637
|
10.0 |
HIGH
|
padl_software
|
pam_ldap
|
Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the …
|
NVD-CWE-Other
|
CVE-2003-0734
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356638
|
10.0 |
HIGH
|
castle_rock_computing
|
snmpc
|
SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.
|
NVD-CWE-Other
|
CVE-2003-0745
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356639
|
7.5 |
HIGH
|
py-membres
|
py-membres
|
secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.
|
NVD-CWE-Other
|
CVE-2003-0750
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356640
|
7.5 |
HIGH
|
py-membres
|
py-membres
|
SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.
|
NVD-CWE-Other
|
CVE-2003-0751
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356641
|
5.0 |
MEDIUM
|
newsphp
|
newsphp
|
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.
|
NVD-CWE-Other
|
CVE-2003-0753
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356642
|
7.5 |
HIGH
|
newsphp
|
newsphp
|
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
|
NVD-CWE-Other
|
CVE-2003-0754
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356643
|
10.0 |
HIGH
|
gtkftpd
|
gtkftp
|
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.
|
NVD-CWE-Other
|
CVE-2003-0755
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356644
|
5.0 |
MEDIUM
|
sitebuilder
|
sitebuilder
|
Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.
|
NVD-CWE-Other
|
CVE-2003-0756
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356645
|
7.5 |
HIGH
|
foxweb
|
foxweb
|
Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).
|
NVD-CWE-Other
|
CVE-2003-0762
|
2008-09-11 04:20 |
2003-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356646
|
7.5 |
HIGH
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.
|
NVD-CWE-Other
|
CVE-2003-0774
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356647
|
5.0 |
MEDIUM
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of s…
|
NVD-CWE-Other
|
CVE-2003-0775
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356648
|
7.5 |
HIGH
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.
|
NVD-CWE-Other
|
CVE-2003-0776
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356649
|
5.0 |
MEDIUM
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of ser…
|
NVD-CWE-Other
|
CVE-2003-0777
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356650
|
5.0 |
MEDIUM
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption…
|
NVD-CWE-Other
|
CVE-2003-0778
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|