VYPR

CVEs

378,263 total · page 7408 of 7,566

  • CVE-2003-1111Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in multiple dynamicsoft products including y and certain demo products for AppEngine allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG…

  • CVE-2003-1112Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in Ingate Firewall and Ingate SIParator before 3.1.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

  • CVE-2003-1113Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

  • CVE-2003-1114Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways running SIPv2.4 and SIPv4.3 firmware allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the…

  • CVE-2003-1115Dec 31, 2003
    risk 0.00cvss epss 0.05

    The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG…

  • CVE-2003-1116Dec 31, 2003
    risk 0.00cvss epss 0.04

    The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications…

  • CVE-2003-1117Dec 31, 2003
    risk 0.00cvss epss 0.05

    Buffer overflow in RealSystem Server 6.x, 7.x and 8.x, and RealSystem Proxy 8.x, related to URL error handling, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

  • CVE-2003-1118Dec 31, 2003
    risk 0.04cvss epss 0.18

    Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.

  • CVE-2003-1119Dec 31, 2003
    risk 0.00cvss epss 0.02

    SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.

  • CVE-2003-1120Dec 31, 2003
    risk 0.00cvss epss 0.00

    Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.

  • CVE-2003-1121Dec 31, 2003
    risk 0.00cvss epss 0.04

    Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the…

  • CVE-2003-1122Dec 31, 2003
    risk 0.00cvss epss 0.01

    ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.

  • CVE-2003-1123Dec 31, 2003
    risk 0.04cvss epss 0.11

    Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.

  • CVE-2003-1124Dec 31, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Sun Management Center (SunMC) 2.1.1, 3.0, and 3.0 Revenue Release (RR), when installed and run by root, allows local users to create or modify arbitrary files.

  • CVE-2003-1125Dec 31, 2003
    risk 0.00cvss epss 0.01

    Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).

  • CVE-2003-1126Dec 31, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.

  • CVE-2003-1127Dec 31, 2003
    risk 0.00cvss epss 0.02

    Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.

  • CVE-2003-1128Dec 31, 2003
    risk 0.00cvss epss 0.03

    XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.

  • CVE-2003-1129Dec 31, 2003
    risk 0.04cvss epss 0.08

    Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.

  • CVE-2003-1131Dec 31, 2003
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.

  • CVE-2003-1132Dec 31, 2003
    risk 0.00cvss epss 0.02

    The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service…

  • CVE-2003-1133Dec 31, 2003
    risk 0.00cvss epss 0.00

    Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.

  • CVE-2003-1134Dec 31, 2003
    risk 0.03cvss epss 0.01

    Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.

  • CVE-2003-1135Dec 31, 2003
    risk 0.03cvss epss 0.05

    Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

  • CVE-2003-1152Dec 31, 2003
    risk 0.00cvss epss 0.02

    WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").

  • CVE-2003-1153Dec 31, 2003
    risk 0.00cvss epss 0.02

    byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.

  • CVE-2003-1154Dec 31, 2003
    risk 0.00cvss epss 0.02

    MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.

  • CVE-2003-1155Dec 31, 2003
    risk 0.00cvss epss 0.00

    X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.

  • CVE-2003-1156Dec 31, 2003
    risk 0.00cvss epss 0.01

    Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

  • CVE-2003-1157Dec 31, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.

  • CVE-2003-1158Dec 31, 2003
    risk 0.03cvss epss 0.03

    Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.

  • CVE-2003-1161Dec 31, 2003
    risk 0.00cvss epss 0.00

    exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.

  • CVE-2003-1162Dec 31, 2003
    risk 0.03cvss epss 0.03

    index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.

  • CVE-2003-1163Dec 31, 2003
    risk 0.00cvss epss 0.02

    hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.

  • CVE-2003-1164Dec 31, 2003
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.

  • CVE-2003-1165Dec 31, 2003
    risk 0.03cvss epss 0.06

    Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.

  • CVE-2003-1166Dec 31, 2003
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2003-1167Dec 31, 2003
    risk 0.03cvss epss 0.01

    misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.

  • CVE-2003-1168Dec 31, 2003
    risk 0.00cvss epss 0.02

    HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.

  • CVE-2003-1169Dec 31, 2003
    risk 0.03cvss epss 0.01

    DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.

  • CVE-2003-1170Dec 31, 2003
    risk 0.00cvss epss 0.01

    Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments.

  • CVE-2003-1171Dec 31, 2003
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.

  • CVE-2003-1172Dec 31, 2003
    risk 0.05cvss epss 0.31

    Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.

  • CVE-2003-1173Dec 31, 2003
    risk 0.03cvss epss 0.03

    Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.

  • CVE-2003-1174Dec 31, 2003
    risk 0.03cvss epss 0.01

    Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.

  • CVE-2003-1175Dec 31, 2003
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.

  • CVE-2003-1176Dec 31, 2003
    risk 0.04cvss epss 0.07

    post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.

  • CVE-2003-1177Dec 31, 2003
    risk 0.04cvss epss 0.13

    Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.

  • CVE-2003-1178Dec 31, 2003
    risk 0.00cvss epss 0.02

    Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.

  • CVE-2003-1179Dec 31, 2003
    risk 0.03cvss epss 0.05

    Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.