VYPR

CVEs

343,267 total · page 6717 of 6,866

  • CVE-2003-1056Dec 11, 2003
    risk 0.00cvss epss 0.00

    The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2003-1057Dec 8, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.

  • CVE-2003-1058Dec 3, 2003
    risk 0.00cvss epss 0.00

    The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on temporary server files.

  • CVE-2003-0564Dec 1, 2003
    risk 0.01cvss epss 0.08

    Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected…

  • CVE-2003-0565Dec 1, 2003
    risk 0.00cvss epss 0.03

    Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test…

  • CVE-2003-0621Dec 1, 2003
    risk 0.04cvss epss 0.07

    The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.

  • CVE-2003-0622Dec 1, 2003
    risk 0.00cvss epss 0.02

    The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.

  • CVE-2003-0623Dec 1, 2003
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.

  • CVE-2003-0624Dec 1, 2003
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.

  • CVE-2003-0788Dec 1, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).

  • CVE-2003-0834Dec 1, 2003
    risk 0.03cvss epss 0.01

    Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.

  • CVE-2003-0851Dec 1, 2003
    risk 0.00cvss epss 0.05

    OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.

  • CVE-2003-0886Dec 1, 2003
    risk 0.04cvss epss 0.12

    Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.

  • CVE-2003-0913Dec 1, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "unauthorized access."

  • CVE-2003-0925Dec 1, 2003
    risk 0.00cvss epss 0.06

    Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.

  • CVE-2003-0926Dec 1, 2003
    risk 0.00cvss epss 0.03

    Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.

  • CVE-2003-0927Dec 1, 2003
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.

  • CVE-2003-0933Dec 1, 2003
    risk 0.00cvss epss 0.00

    Buffer overflow in conquest 7.2 and earlier may allow a local user to execute arbitrary code via a long environment variable.

  • CVE-2003-0934Dec 1, 2003
    risk 0.00cvss epss 0.00

    Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.

  • CVE-2003-0935Dec 1, 2003
    risk 0.00cvss epss 0.01

    Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.

  • CVE-2003-1216Nov 27, 2003
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.

  • CVE-2003-1084Nov 24, 2003
    risk 0.00cvss epss 0.04

    Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.

  • CVE-2003-1195Nov 23, 2003
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable.

  • CVE-2003-1059Nov 20, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.

  • CVE-2001-1411Nov 17, 2003
    risk 0.00cvss epss 0.00

    Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.

  • CVE-2001-1412Nov 17, 2003
    risk 0.03cvss epss 0.01

    nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.

  • CVE-2002-1568Nov 17, 2003
    risk 0.00cvss epss 0.03

    OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2…

  • CVE-2002-1569Nov 17, 2003
    risk 0.00cvss epss 0.02

    gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file.

  • CVE-2003-0543Nov 17, 2003
    risk 0.05cvss epss 0.25

    Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.

  • CVE-2003-0544Nov 17, 2003
    risk 0.00cvss epss 0.06

    OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.

  • CVE-2003-0545CriNov 17, 2003
    risk 0.71cvss 9.8epss 0.85

    Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.

  • CVE-2003-0659Nov 17, 2003
    risk 0.06cvss epss 0.34

    Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.

  • CVE-2003-0660Nov 17, 2003
    risk 0.02cvss epss 0.23

    The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.

  • CVE-2003-0662Nov 17, 2003
    risk 0.03cvss epss 0.34

    Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.

  • CVE-2003-0711Nov 17, 2003
    risk 0.03cvss epss 0.33

    Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.

  • CVE-2003-0712Nov 17, 2003
    risk 0.01cvss epss 0.17

    Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.

  • CVE-2003-0714Nov 17, 2003
    risk 0.09cvss epss 0.76

    The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange…

  • CVE-2003-0717Nov 17, 2003
    risk 0.08cvss epss 0.63

    The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

  • CVE-2003-0786Nov 17, 2003
    risk 0.00cvss epss 0.03

    The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.

  • CVE-2003-0787Nov 17, 2003
    risk 0.00cvss epss 0.02

    The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.

  • CVE-2003-0792Nov 17, 2003
    risk 0.00cvss epss 0.02

    Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.

  • CVE-2003-0793Nov 17, 2003
    risk 0.00cvss epss 0.00

    GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).

  • CVE-2003-0794Nov 17, 2003
    risk 0.00cvss epss 0.00

    GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.

  • CVE-2003-0804Nov 17, 2003
    risk 0.00cvss epss 0.01

    The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.

  • CVE-2003-0809Nov 17, 2003
    risk 0.05cvss epss 0.27

    Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.

  • CVE-2003-0813Nov 17, 2003
    risk 0.01cvss epss 0.15

    A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it…

  • CVE-2003-0830Nov 17, 2003
    risk 0.03cvss epss 0.01

    Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.

  • CVE-2003-0831Nov 17, 2003
    risk 0.07cvss epss 0.55

    ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.

  • CVE-2003-0832Nov 17, 2003
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header.

  • CVE-2003-0833Nov 17, 2003
    risk 0.04cvss epss 0.06

    Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname.