VYPR

CVEs

343,281 total · page 6708 of 6,866

  • CVE-2003-1093Dec 31, 2003
    risk 0.00cvss epss 0.00

    BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException.

  • CVE-2003-1094Dec 31, 2003
    risk 0.00cvss epss 0.01

    BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.

  • CVE-2003-1096Dec 31, 2003
    risk 0.04cvss epss 0.10

    The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.

  • CVE-2003-1097Dec 31, 2003
    risk 0.03cvss epss 0.04

    Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.

  • CVE-2003-1098Dec 31, 2003
    risk 0.00cvss epss 0.01

    The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.

  • CVE-2003-1099Dec 31, 2003
    risk 0.00cvss epss 0.01

    shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.

  • CVE-2003-1100Dec 31, 2003
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors.

  • CVE-2003-1101Dec 31, 2003
    risk 0.00cvss epss 0.02

    Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message.

  • CVE-2003-1102Dec 31, 2003
    risk 0.00cvss epss 0.02

    Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.

  • CVE-2003-1103Dec 31, 2003
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands.

  • CVE-2003-1104Dec 31, 2003
    risk 0.01cvss epss 0.07

    Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors.

  • CVE-2003-1105Dec 31, 2003
    risk 0.01cvss epss 0.18

    Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.

  • CVE-2003-1106Dec 31, 2003
    risk 0.00cvss epss 0.02

    The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.

  • CVE-2003-1107Dec 31, 2003
    risk 0.00cvss epss 0.05

    The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions.

  • CVE-2003-1108Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

  • CVE-2003-1109Dec 31, 2003
    risk 0.01cvss epss 0.07

    The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via…

  • CVE-2003-1110Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in Columbia SIP User Agent (sipc) 1.74 and other versions before sipc 2.0 build 2003-02-21 allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the…

  • CVE-2003-1111Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in multiple dynamicsoft products including y and certain demo products for AppEngine allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG…

  • CVE-2003-1112Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in Ingate Firewall and Ingate SIParator before 3.1.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

  • CVE-2003-1113Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

  • CVE-2003-1114Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways running SIPv2.4 and SIPv4.3 firmware allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the…

  • CVE-2003-1115Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG…

  • CVE-2003-1116Dec 31, 2003
    risk 0.00cvss epss 0.04

    The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications…

  • CVE-2003-1117Dec 31, 2003
    risk 0.00cvss epss 0.05

    Buffer overflow in RealSystem Server 6.x, 7.x and 8.x, and RealSystem Proxy 8.x, related to URL error handling, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

  • CVE-2003-1118Dec 31, 2003
    risk 0.04cvss epss 0.18

    Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.

  • CVE-2003-1119Dec 31, 2003
    risk 0.00cvss epss 0.02

    SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.

  • CVE-2003-1120Dec 31, 2003
    risk 0.00cvss epss 0.00

    Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.

  • CVE-2003-1121Dec 31, 2003
    risk 0.00cvss epss 0.04

    Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the…

  • CVE-2003-1122Dec 31, 2003
    risk 0.00cvss epss 0.01

    ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.

  • CVE-2003-1123Dec 31, 2003
    risk 0.04cvss epss 0.11

    Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.

  • CVE-2003-1124Dec 31, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Sun Management Center (SunMC) 2.1.1, 3.0, and 3.0 Revenue Release (RR), when installed and run by root, allows local users to create or modify arbitrary files.

  • CVE-2003-1125Dec 31, 2003
    risk 0.00cvss epss 0.01

    Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).

  • CVE-2003-1126Dec 31, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.

  • CVE-2003-1127Dec 31, 2003
    risk 0.00cvss epss 0.02

    Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.

  • CVE-2003-1128Dec 31, 2003
    risk 0.00cvss epss 0.03

    XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.

  • CVE-2003-1129Dec 31, 2003
    risk 0.04cvss epss 0.08

    Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.

  • CVE-2003-1131Dec 31, 2003
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.

  • CVE-2003-1132Dec 31, 2003
    risk 0.00cvss epss 0.02

    The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service…

  • CVE-2003-1133Dec 31, 2003
    risk 0.00cvss epss 0.00

    Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.

  • CVE-2003-1134Dec 31, 2003
    risk 0.03cvss epss 0.01

    Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.

  • CVE-2003-1135Dec 31, 2003
    risk 0.03cvss epss 0.05

    Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

  • CVE-2003-1152Dec 31, 2003
    risk 0.00cvss epss 0.02

    WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").

  • CVE-2003-1153Dec 31, 2003
    risk 0.00cvss epss 0.02

    byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.

  • CVE-2003-1154Dec 31, 2003
    risk 0.00cvss epss 0.02

    MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.

  • CVE-2003-1155Dec 31, 2003
    risk 0.00cvss epss 0.00

    X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.

  • CVE-2003-1156Dec 31, 2003
    risk 0.00cvss epss 0.01

    Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

  • CVE-2003-1157Dec 31, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.

  • CVE-2003-1158Dec 31, 2003
    risk 0.03cvss epss 0.03

    Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.

  • CVE-2003-1161Dec 31, 2003
    risk 0.00cvss epss 0.00

    exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.

  • CVE-2003-1162Dec 31, 2003
    risk 0.03cvss epss 0.03

    index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.