| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2003-0517 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2003 | faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files. | ||
| CVE-2003-0518 | 0.00 | — | 0.00 | Aug 18, 2003 | The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow. | |||
| CVE-2003-0519 | 0.01 | — | 0.11 | Aug 18, 2003 | Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices. | |||
| CVE-2003-0520 | 0.00 | — | 0.01 | Aug 18, 2003 | Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified. | |||
| CVE-2003-0521 | 0.03 | — | 0.02 | Aug 18, 2003 | Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors… | |||
| CVE-2003-0522 | 0.00 | — | 0.02 | Aug 18, 2003 | Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp. | |||
| CVE-2003-0523 | 0.03 | — | 0.03 | Aug 18, 2003 | Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter. | |||
| CVE-2003-0524 | 0.00 | — | 0.00 | Aug 18, 2003 | Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory. | |||
| CVE-2003-0526 | 0.05 | — | 0.22 | Aug 18, 2003 | Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages… | |||
| CVE-2003-0535 | 0.00 | — | 0.00 | Aug 18, 2003 | Buffer overflow in xbl 1.0k and earlier allows local users to gain privileges via a long -display command line option. | |||
| CVE-2003-0536 | 0.03 | — | 0.01 | Aug 18, 2003 | Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters. | |||
| CVE-2003-0537 | 0.00 | — | 0.00 | Aug 18, 2003 | The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users. | |||
| CVE-2003-0538 | 0.00 | — | 0.01 | Aug 18, 2003 | The mailcap file for mozart 1.2.5 and earlier causes Oz applications to be passed to the Oz interpreter, which allows remote attackers to execute arbitrary Oz programs in a MIME-aware client program. | |||
| CVE-2003-0539 | 0.00 | — | 0.00 | Aug 18, 2003 | skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files. | |||
| CVE-2003-0553 | 0.00 | — | 0.03 | Aug 18, 2003 | Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename. | |||
| CVE-2003-0554 | 0.00 | — | 0.01 | Aug 18, 2003 | NeoModus Direct Connect 1.0 build 9, and possibly other versions, allows remote attackers to cause a denial of service (connection and possibly memory exhaustion) via a flood of ConnectToMe requests containing arbitrary IP addresses and ports. | |||
| CVE-2003-0555 | 0.00 | — | 0.02 | Aug 18, 2003 | ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability. | |||
| CVE-2003-0556 | 0.00 | — | 0.01 | Aug 18, 2003 | Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester. | |||
| CVE-2003-0557 | 0.03 | — | 0.01 | Aug 18, 2003 | SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field. | |||
| CVE-2003-0558 | 0.08 | — | 0.56 | Aug 18, 2003 | Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request. | |||
| CVE-2003-0559 | 0.00 | — | 0.01 | Aug 18, 2003 | mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code. | |||
| CVE-2003-0560 | 0.03 | — | 0.03 | Aug 18, 2003 | SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter. | |||
| CVE-2003-0561 | 0.03 | — | 0.04 | Aug 18, 2003 | Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands. | |||
| CVE-2003-0567 | 0.04 | — | 0.17 | Aug 18, 2003 | Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full. | |||
| CVE-2003-0572 | 0.00 | — | 0.01 | Aug 18, 2003 | Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption). | |||
| CVE-2003-0573 | 0.00 | — | 0.01 | Aug 18, 2003 | The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact. | |||
| CVE-2003-0574 | 0.00 | — | 0.00 | Aug 18, 2003 | Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028. | |||
| CVE-2003-0577 | — | 0.00 | — | 0.04 | Aug 18, 2003 | mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which creates a negative frame size. | ||
| CVE-2003-0578 | Hig | 0.51 | 7.8 | 0.00 | Aug 18, 2003 | cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files. | ||
| CVE-2003-0579 | 0.03 | — | 0.01 | Aug 18, 2003 | uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user. | |||
| CVE-2003-0580 | 0.00 | — | 0.01 | Aug 18, 2003 | Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument. | |||
| CVE-2003-0581 | 0.00 | — | 0.03 | Aug 18, 2003 | X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an… | |||
| CVE-2003-0583 | 0.00 | — | 0.00 | Aug 18, 2003 | Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument. | |||
| CVE-2003-0584 | 0.03 | — | 0.01 | Aug 18, 2003 | Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument. | |||
| CVE-2003-0585 | 0.00 | — | 0.02 | Aug 18, 2003 | SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters. | |||
| CVE-2003-0586 | 0.03 | — | 0.06 | Aug 18, 2003 | Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php. | |||
| CVE-2003-0587 | 0.00 | — | 0.01 | Aug 18, 2003 | Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie. | |||
| CVE-2003-0588 | 0.00 | — | 0.03 | Aug 18, 2003 | admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password. | |||
| CVE-2003-0589 | 0.00 | — | 0.03 | Aug 18, 2003 | admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password. | |||
| CVE-2003-0590 | 0.03 | — | 0.02 | Aug 18, 2003 | Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field. | |||
| CVE-1999-1263 | 0.00 | — | 0.01 | Aug 15, 2003 | Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file. | |||
| CVE-2003-1088 | 0.03 | — | 0.02 | Aug 11, 2003 | Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter. | |||
| CVE-2003-0449 | 0.03 | — | 0.01 | Aug 7, 2003 | Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir… | |||
| CVE-2003-0450 | 0.00 | — | 0.04 | Aug 7, 2003 | Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow. | |||
| CVE-2003-0451 | 0.00 | — | 0.00 | Aug 7, 2003 | Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments. | |||
| CVE-2003-0452 | 0.00 | — | 0.00 | Aug 7, 2003 | Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections." | |||
| CVE-2003-0453 | 0.00 | — | 0.03 | Aug 7, 2003 | traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow. | |||
| CVE-2003-0454 | 0.03 | — | 0.03 | Aug 7, 2003 | Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable. | |||
| CVE-2003-0455 | 0.00 | — | 0.00 | Aug 7, 2003 | The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files. | |||
| CVE-2003-0469 | 0.07 | — | 0.50 | Aug 7, 2003 | Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align"… |
- risk 0.36cvss 5.5epss 0.00
faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.
- CVE-2003-0518Aug 18, 2003risk 0.00cvss —epss 0.00
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, possibly triggering a buffer overflow.
- CVE-2003-0519Aug 18, 2003risk 0.01cvss —epss 0.11
Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.
- CVE-2003-0520Aug 18, 2003risk 0.00cvss —epss 0.01
Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.
- CVE-2003-0521Aug 18, 2003risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors…
- CVE-2003-0522Aug 18, 2003risk 0.00cvss —epss 0.02
Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.
- CVE-2003-0523Aug 18, 2003risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.
- CVE-2003-0524Aug 18, 2003risk 0.00cvss —epss 0.00
Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.
- CVE-2003-0526Aug 18, 2003risk 0.05cvss —epss 0.22
Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages…
- CVE-2003-0535Aug 18, 2003risk 0.00cvss —epss 0.00
Buffer overflow in xbl 1.0k and earlier allows local users to gain privileges via a long -display command line option.
- CVE-2003-0536Aug 18, 2003risk 0.03cvss —epss 0.01
Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters.
- CVE-2003-0537Aug 18, 2003risk 0.00cvss —epss 0.00
The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.
- CVE-2003-0538Aug 18, 2003risk 0.00cvss —epss 0.01
The mailcap file for mozart 1.2.5 and earlier causes Oz applications to be passed to the Oz interpreter, which allows remote attackers to execute arbitrary Oz programs in a MIME-aware client program.
- CVE-2003-0539Aug 18, 2003risk 0.00cvss —epss 0.00
skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.
- CVE-2003-0553Aug 18, 2003risk 0.00cvss —epss 0.03
Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.
- CVE-2003-0554Aug 18, 2003risk 0.00cvss —epss 0.01
NeoModus Direct Connect 1.0 build 9, and possibly other versions, allows remote attackers to cause a denial of service (connection and possibly memory exhaustion) via a flood of ConnectToMe requests containing arbitrary IP addresses and ports.
- CVE-2003-0555Aug 18, 2003risk 0.00cvss —epss 0.02
ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability.
- CVE-2003-0556Aug 18, 2003risk 0.00cvss —epss 0.01
Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.
- CVE-2003-0557Aug 18, 2003risk 0.03cvss —epss 0.01
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.
- CVE-2003-0558Aug 18, 2003risk 0.08cvss —epss 0.56
Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.
- CVE-2003-0559Aug 18, 2003risk 0.00cvss —epss 0.01
mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.
- CVE-2003-0560Aug 18, 2003risk 0.03cvss —epss 0.03
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.
- CVE-2003-0561Aug 18, 2003risk 0.03cvss —epss 0.04
Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.
- CVE-2003-0567Aug 18, 2003risk 0.04cvss —epss 0.17
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.
- CVE-2003-0572Aug 18, 2003risk 0.00cvss —epss 0.01
Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).
- CVE-2003-0573Aug 18, 2003risk 0.00cvss —epss 0.01
The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.
- CVE-2003-0574Aug 18, 2003risk 0.00cvss —epss 0.00
Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028.
- CVE-2003-0577Aug 18, 2003risk 0.00cvss —epss 0.04
mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which creates a negative frame size.
- risk 0.51cvss 7.8epss 0.00
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
- CVE-2003-0579Aug 18, 2003risk 0.03cvss —epss 0.01
uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.
- CVE-2003-0580Aug 18, 2003risk 0.00cvss —epss 0.01
Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.
- CVE-2003-0581Aug 18, 2003risk 0.00cvss —epss 0.03
X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an…
- CVE-2003-0583Aug 18, 2003risk 0.00cvss —epss 0.00
Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument.
- CVE-2003-0584Aug 18, 2003risk 0.03cvss —epss 0.01
Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.
- CVE-2003-0585Aug 18, 2003risk 0.00cvss —epss 0.02
SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.
- CVE-2003-0586Aug 18, 2003risk 0.03cvss —epss 0.06
Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.
- CVE-2003-0587Aug 18, 2003risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.
- CVE-2003-0588Aug 18, 2003risk 0.00cvss —epss 0.03
admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.
- CVE-2003-0589Aug 18, 2003risk 0.00cvss —epss 0.03
admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.
- CVE-2003-0590Aug 18, 2003risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.
- CVE-1999-1263Aug 15, 2003risk 0.00cvss —epss 0.01
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.
- CVE-2003-1088Aug 11, 2003risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.
- CVE-2003-0449Aug 7, 2003risk 0.03cvss —epss 0.01
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir…
- CVE-2003-0450Aug 7, 2003risk 0.00cvss —epss 0.04
Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow.
- CVE-2003-0451Aug 7, 2003risk 0.00cvss —epss 0.00
Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.
- CVE-2003-0452Aug 7, 2003risk 0.00cvss —epss 0.00
Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."
- CVE-2003-0453Aug 7, 2003risk 0.00cvss —epss 0.03
traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.
- CVE-2003-0454Aug 7, 2003risk 0.03cvss —epss 0.03
Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.
- CVE-2003-0455Aug 7, 2003risk 0.00cvss —epss 0.00
The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.
- CVE-2003-0469Aug 7, 2003risk 0.07cvss —epss 0.50
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align"…