| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2003-0233 | 0.02 | — | 0.19 | May 12, 2003 | Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115. | |||
| CVE-2003-1146 | 0.03 | — | 0.03 | May 11, 2003 | Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | |||
| CVE-2003-0334 | 0.00 | — | 0.00 | May 10, 2003 | BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c. | |||
| CVE-2003-0110 | 0.01 | — | 0.18 | May 5, 2003 | The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port… | |||
| CVE-2003-0111 | 0.06 | — | 0.41 | May 5, 2003 | The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could… | |||
| CVE-2003-0133 | 0.00 | — | 0.02 | May 5, 2003 | GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages. | |||
| CVE-2003-0136 | 0.00 | — | 0.00 | May 5, 2003 | psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file. | |||
| CVE-2003-0163 | 0.00 | — | 0.01 | May 5, 2003 | decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte. | |||
| CVE-2003-0171 | 0.03 | — | 0.01 | May 5, 2003 | DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program. | |||
| CVE-2003-0173 | 0.00 | — | 0.00 | May 5, 2003 | xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges. | |||
| CVE-2003-0196 | 0.02 | — | 0.23 | May 5, 2003 | Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201. | |||
| CVE-2003-0198 | 0.00 | — | 0.01 | May 5, 2003 | Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files. | |||
| CVE-2003-0201 | 0.10 | — | 0.84 | May 5, 2003 | Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code. | |||
| CVE-2003-0204 | 0.00 | — | 0.04 | May 5, 2003 | KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer. | |||
| CVE-2003-0207 | 0.00 | — | 0.00 | May 5, 2003 | ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files. | |||
| CVE-2003-0208 | 0.00 | — | 0.01 | May 5, 2003 | Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field. | |||
| CVE-2003-0209 | 0.06 | — | 0.38 | May 5, 2003 | Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow. | |||
| CVE-2003-0211 | 0.04 | — | 0.09 | May 5, 2003 | Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections. | |||
| CVE-2003-1070 | 0.00 | — | 0.02 | Apr 28, 2003 | Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash). | |||
| CVE-2003-1072 | 0.00 | — | 0.00 | Apr 28, 2003 | Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption). | |||
| CVE-2002-1464 | 0.00 | — | 0.02 | Apr 22, 2003 | Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable. | |||
| CVE-2002-1465 | 0.00 | — | 0.01 | Apr 22, 2003 | SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable. | |||
| CVE-2002-1466 | 0.00 | — | 0.03 | Apr 22, 2003 | CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable. | |||
| CVE-2002-1467 | 0.00 | — | 0.02 | Apr 22, 2003 | Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file). | |||
| CVE-2002-1468 | 0.03 | — | 0.04 | Apr 22, 2003 | Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root. | |||
| CVE-2002-1469 | 0.03 | — | 0.03 | Apr 22, 2003 | scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those… | |||
| CVE-2002-1470 | 0.00 | — | 0.00 | Apr 22, 2003 | SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file. | |||
| CVE-2002-1471 | 0.00 | — | 0.01 | Apr 22, 2003 | The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack. | |||
| CVE-2002-1473 | 0.03 | — | 0.04 | Apr 22, 2003 | Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code. | |||
| CVE-2002-1474 | 0.00 | — | 0.02 | Apr 22, 2003 | Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service. | |||
| CVE-2002-1475 | 0.00 | — | 0.02 | Apr 22, 2003 | Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service. | |||
| CVE-2002-1476 | 0.00 | — | 0.00 | Apr 22, 2003 | Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the… | |||
| CVE-2002-1477 | 0.00 | — | 0.02 | Apr 22, 2003 | graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode. | |||
| CVE-2002-1478 | 0.00 | — | 0.03 | Apr 22, 2003 | Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode. | |||
| CVE-2002-1479 | 0.00 | — | 0.00 | Apr 22, 2003 | Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges. | |||
| CVE-2002-1480 | 0.03 | — | 0.04 | Apr 22, 2003 | Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry. | |||
| CVE-2002-1481 | 0.04 | — | 0.07 | Apr 22, 2003 | savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php. | |||
| CVE-2002-1482 | 0.03 | — | 0.04 | Apr 22, 2003 | SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry. | |||
| CVE-2002-1483 | 0.04 | — | 0.08 | Apr 22, 2003 | db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot). | |||
| CVE-2002-1484 | Cri | 0.68 | 9.8 | 0.14 | Apr 22, 2003 | DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in… | ||
| CVE-2003-1054 | 0.04 | — | 0.07 | Apr 16, 2003 | mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference. | |||
| CVE-2002-0690 | 0.01 | — | 0.08 | Apr 11, 2003 | Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings. | |||
| CVE-2002-1143 | 0.07 | — | 0.54 | Apr 11, 2003 | Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and… | |||
| CVE-2002-1406 | 0.00 | — | 0.01 | Apr 11, 2003 | Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior." | |||
| CVE-2002-1407 | 0.00 | — | 0.01 | Apr 11, 2003 | TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack. | |||
| CVE-2002-1408 | 0.00 | — | 0.02 | Apr 11, 2003 | Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name. | |||
| CVE-2002-1409 | 0.00 | — | 0.01 | Apr 11, 2003 | ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state." | |||
| CVE-2002-1410 | 0.03 | — | 0.03 | Apr 11, 2003 | Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi. | |||
| CVE-2002-1411 | 0.00 | — | 0.04 | Apr 11, 2003 | Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter. | |||
| CVE-2002-1412 | 0.06 | — | 0.40 | Apr 11, 2003 | Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script. |
- CVE-2003-0233May 12, 2003risk 0.02cvss —epss 0.19
Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.
- CVE-2003-1146May 11, 2003risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
- CVE-2003-0334May 10, 2003risk 0.00cvss —epss 0.00
BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.
- CVE-2003-0110May 5, 2003risk 0.01cvss —epss 0.18
The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port…
- CVE-2003-0111May 5, 2003risk 0.06cvss —epss 0.41
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could…
- CVE-2003-0133May 5, 2003risk 0.00cvss —epss 0.02
GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.
- CVE-2003-0136May 5, 2003risk 0.00cvss —epss 0.00
psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.
- CVE-2003-0163May 5, 2003risk 0.00cvss —epss 0.01
decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.
- CVE-2003-0171May 5, 2003risk 0.03cvss —epss 0.01
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
- CVE-2003-0173May 5, 2003risk 0.00cvss —epss 0.00
xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.
- CVE-2003-0196May 5, 2003risk 0.02cvss —epss 0.23
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.
- CVE-2003-0198May 5, 2003risk 0.00cvss —epss 0.01
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
- CVE-2003-0201May 5, 2003risk 0.10cvss —epss 0.84
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
- CVE-2003-0204May 5, 2003risk 0.00cvss —epss 0.04
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
- CVE-2003-0207May 5, 2003risk 0.00cvss —epss 0.00
ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.
- CVE-2003-0208May 5, 2003risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.
- CVE-2003-0209May 5, 2003risk 0.06cvss —epss 0.38
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.
- CVE-2003-0211May 5, 2003risk 0.04cvss —epss 0.09
Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.
- CVE-2003-1070Apr 28, 2003risk 0.00cvss —epss 0.02
Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).
- CVE-2003-1072Apr 28, 2003risk 0.00cvss —epss 0.00
Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).
- CVE-2002-1464Apr 22, 2003risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.
- CVE-2002-1465Apr 22, 2003risk 0.00cvss —epss 0.01
SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.
- CVE-2002-1466Apr 22, 2003risk 0.00cvss —epss 0.03
CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.
- CVE-2002-1467Apr 22, 2003risk 0.00cvss —epss 0.02
Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).
- CVE-2002-1468Apr 22, 2003risk 0.03cvss —epss 0.04
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
- CVE-2002-1469Apr 22, 2003risk 0.03cvss —epss 0.03
scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those…
- CVE-2002-1470Apr 22, 2003risk 0.00cvss —epss 0.00
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.
- CVE-2002-1471Apr 22, 2003risk 0.00cvss —epss 0.01
The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.
- CVE-2002-1473Apr 22, 2003risk 0.03cvss —epss 0.04
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.
- CVE-2002-1474Apr 22, 2003risk 0.00cvss —epss 0.02
Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service.
- CVE-2002-1475Apr 22, 2003risk 0.00cvss —epss 0.02
Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service.
- CVE-2002-1476Apr 22, 2003risk 0.00cvss —epss 0.00
Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the…
- CVE-2002-1477Apr 22, 2003risk 0.00cvss —epss 0.02
graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.
- CVE-2002-1478Apr 22, 2003risk 0.00cvss —epss 0.03
Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.
- CVE-2002-1479Apr 22, 2003risk 0.00cvss —epss 0.00
Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.
- CVE-2002-1480Apr 22, 2003risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.
- CVE-2002-1481Apr 22, 2003risk 0.04cvss —epss 0.07
savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.
- CVE-2002-1482Apr 22, 2003risk 0.03cvss —epss 0.04
SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.
- CVE-2002-1483Apr 22, 2003risk 0.04cvss —epss 0.08
db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).
- risk 0.68cvss 9.8epss 0.14
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in…
- CVE-2003-1054Apr 16, 2003risk 0.04cvss —epss 0.07
mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.
- CVE-2002-0690Apr 11, 2003risk 0.01cvss —epss 0.08
Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.
- CVE-2002-1143Apr 11, 2003risk 0.07cvss —epss 0.54
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and…
- CVE-2002-1406Apr 11, 2003risk 0.00cvss —epss 0.01
Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."
- CVE-2002-1407Apr 11, 2003risk 0.00cvss —epss 0.01
TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.
- CVE-2002-1408Apr 11, 2003risk 0.00cvss —epss 0.02
Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name.
- CVE-2002-1409Apr 11, 2003risk 0.00cvss —epss 0.01
ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state."
- CVE-2002-1410Apr 11, 2003risk 0.03cvss —epss 0.03
Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.
- CVE-2002-1411Apr 11, 2003risk 0.00cvss —epss 0.04
Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.
- CVE-2002-1412Apr 11, 2003risk 0.06cvss —epss 0.40
Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script.