VYPR

CVEs

343,083 total · page 6727 of 6,862

  • CVE-2003-0233May 12, 2003
    risk 0.02cvss epss 0.19

    Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.

  • CVE-2003-1146May 11, 2003
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

  • CVE-2003-0334May 10, 2003
    risk 0.00cvss epss 0.00

    BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.

  • CVE-2003-0110May 5, 2003
    risk 0.01cvss epss 0.18

    The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port…

  • CVE-2003-0111May 5, 2003
    risk 0.06cvss epss 0.41

    The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could…

  • CVE-2003-0133May 5, 2003
    risk 0.00cvss epss 0.02

    GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.

  • CVE-2003-0136May 5, 2003
    risk 0.00cvss epss 0.00

    psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.

  • CVE-2003-0163May 5, 2003
    risk 0.00cvss epss 0.01

    decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.

  • CVE-2003-0171May 5, 2003
    risk 0.03cvss epss 0.01

    DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.

  • CVE-2003-0173May 5, 2003
    risk 0.00cvss epss 0.00

    xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.

  • CVE-2003-0196May 5, 2003
    risk 0.02cvss epss 0.23

    Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.

  • CVE-2003-0198May 5, 2003
    risk 0.00cvss epss 0.01

    Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.

  • CVE-2003-0201May 5, 2003
    risk 0.10cvss epss 0.84

    Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.

  • CVE-2003-0204May 5, 2003
    risk 0.00cvss epss 0.04

    KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.

  • CVE-2003-0207May 5, 2003
    risk 0.00cvss epss 0.00

    ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.

  • CVE-2003-0208May 5, 2003
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.

  • CVE-2003-0209May 5, 2003
    risk 0.06cvss epss 0.38

    Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.

  • CVE-2003-0211May 5, 2003
    risk 0.04cvss epss 0.09

    Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.

  • CVE-2003-1070Apr 28, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).

  • CVE-2003-1072Apr 28, 2003
    risk 0.00cvss epss 0.00

    Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).

  • CVE-2002-1464Apr 22, 2003
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

  • CVE-2002-1465Apr 22, 2003
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

  • CVE-2002-1466Apr 22, 2003
    risk 0.00cvss epss 0.03

    CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.

  • CVE-2002-1467Apr 22, 2003
    risk 0.00cvss epss 0.02

    Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).

  • CVE-2002-1468Apr 22, 2003
    risk 0.03cvss epss 0.04

    Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.

  • CVE-2002-1469Apr 22, 2003
    risk 0.03cvss epss 0.03

    scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those…

  • CVE-2002-1470Apr 22, 2003
    risk 0.00cvss epss 0.00

    SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.

  • CVE-2002-1471Apr 22, 2003
    risk 0.00cvss epss 0.01

    The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.

  • CVE-2002-1473Apr 22, 2003
    risk 0.03cvss epss 0.04

    Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

  • CVE-2002-1474Apr 22, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service.

  • CVE-2002-1475Apr 22, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service.

  • CVE-2002-1476Apr 22, 2003
    risk 0.00cvss epss 0.00

    Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the…

  • CVE-2002-1477Apr 22, 2003
    risk 0.00cvss epss 0.02

    graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.

  • CVE-2002-1478Apr 22, 2003
    risk 0.00cvss epss 0.03

    Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.

  • CVE-2002-1479Apr 22, 2003
    risk 0.00cvss epss 0.00

    Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.

  • CVE-2002-1480Apr 22, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.

  • CVE-2002-1481Apr 22, 2003
    risk 0.04cvss epss 0.07

    savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.

  • CVE-2002-1482Apr 22, 2003
    risk 0.03cvss epss 0.04

    SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.

  • CVE-2002-1483Apr 22, 2003
    risk 0.04cvss epss 0.08

    db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).

  • CVE-2002-1484CriApr 22, 2003
    risk 0.68cvss 9.8epss 0.14

    DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in…

  • CVE-2003-1054Apr 16, 2003
    risk 0.04cvss epss 0.07

    mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.

  • CVE-2002-0690Apr 11, 2003
    risk 0.01cvss epss 0.08

    Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.

  • CVE-2002-1143Apr 11, 2003
    risk 0.07cvss epss 0.54

    Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and…

  • CVE-2002-1406Apr 11, 2003
    risk 0.00cvss epss 0.01

    Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."

  • CVE-2002-1407Apr 11, 2003
    risk 0.00cvss epss 0.01

    TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.

  • CVE-2002-1408Apr 11, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name.

  • CVE-2002-1409Apr 11, 2003
    risk 0.00cvss epss 0.01

    ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state."

  • CVE-2002-1410Apr 11, 2003
    risk 0.03cvss epss 0.03

    Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.

  • CVE-2002-1411Apr 11, 2003
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.

  • CVE-2002-1412Apr 11, 2003
    risk 0.06cvss epss 0.40

    Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script.