VYPR

CVEs

378,260 total · page 7411 of 7,566

  • CVE-2003-1315Dec 31, 2003
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in auth.php in Land Down Under (LDU) v601 and earlier allows remote attackers to execute arbitrary SQL commands.

  • CVE-2003-1316Dec 31, 2003
    risk 0.00cvss epss 0.01

    mod.php in eNdonesia 8.2 allows remote attackers to obtain sensitive information via a ' (quote) value in the lng parameter, which reveals the path in an error message. NOTE: The provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2003-1317Dec 31, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2003-1318Dec 31, 2003
    risk 0.03cvss epss 0.03

    Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.

  • CVE-2003-1319Dec 31, 2003
    risk 0.00cvss epss 0.05

    Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which…

  • CVE-2003-1320Dec 31, 2003
    risk 0.00cvss epss 0.02

    SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) a large number of…

  • CVE-2003-1321Dec 31, 2003
    risk 0.03cvss epss 0.04

    Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.

  • CVE-2003-1322Dec 31, 2003
    risk 0.00cvss epss 0.06

    Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10)…

  • CVE-2003-1323Dec 31, 2003
    risk 0.00cvss epss 0.01

    Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group via unspecified vectors.

  • CVE-2003-1324Dec 31, 2003
    risk 0.00cvss epss 0.00

    Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.

  • CVE-2003-1325Dec 31, 2003
    risk 0.03cvss epss 0.03

    The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents…

  • CVE-2003-1327Dec 31, 2003
    risk 0.00cvss epss 0.03

    Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which…

  • CVE-2003-1329Dec 31, 2003
    risk 0.00cvss epss 0.01

    ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.

  • CVE-2003-1330Dec 31, 2003
    risk 0.00cvss epss 0.01

    Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.

  • CVE-2003-1331Dec 31, 2003
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.

  • CVE-2003-1332Dec 31, 2003
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.

  • CVE-2003-1333Dec 31, 2003
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.

  • CVE-2003-1334Dec 31, 2003
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2003-1335Dec 31, 2003
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory.

  • CVE-2003-1336Dec 31, 2003
    risk 0.06cvss epss 0.36

    Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.

  • CVE-2003-1337Dec 31, 2003
    risk 0.01cvss epss 0.12

    Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

  • CVE-2003-1338Dec 31, 2003
    risk 0.00cvss epss 0.01

    CRLF injection vulnerability in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to inject arbitrary HTTP headers and possibly conduct HTTP Response Splitting attacks via CRLF sequences in the Location header.

  • CVE-2003-1339Dec 31, 2003
    risk 0.07cvss epss 0.49

    Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cause a denial of service (crash) or execute arbitrary code, as demonstrated via (1) a long GET request and (2) a long operation or…

  • CVE-2003-1340Dec 31, 2003
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to…

  • CVE-2003-1341Dec 31, 2003
    risk 0.04cvss epss 0.08

    The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.

  • CVE-2003-1342Dec 31, 2003
    risk 0.03cvss epss 0.03

    Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via multiple URL requests for ActiveSupport.exe.

  • CVE-2003-1343Dec 31, 2003
    risk 0.03cvss epss 0.03

    Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".

  • CVE-2003-1344Dec 31, 2003
    risk 0.03cvss epss 0.03

    Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.

  • CVE-2003-1345Dec 31, 2003
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter.

  • CVE-2003-1346Dec 31, 2003
    risk 0.00cvss epss 0.02

    D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware using AirPlus Access Point Manager.

  • CVE-2003-1347Dec 31, 2003
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.

  • CVE-2003-1348Dec 31, 2003
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.

  • CVE-2003-1349Dec 31, 2003
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.

  • CVE-2003-1350Dec 31, 2003
    risk 0.03cvss epss 0.02

    List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

  • CVE-2003-1351Dec 31, 2003
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.

  • CVE-2003-1352Dec 31, 2003
    risk 0.00cvss epss 0.01

    Gabber 0.8.7 sends an email to a specific address during user login and logout, which allows remote attackers to obtain user session activity and Gabber version number by sniffing.

  • CVE-2003-1353Dec 31, 2003
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.

  • CVE-2003-1354Dec 31, 2003
    risk 0.03cvss epss 0.06

    Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942.

  • CVE-2003-1355Dec 31, 2003
    risk 0.03cvss epss 0.04

    Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.

  • CVE-2003-1356Dec 31, 2003
    risk 0.00cvss epss 0.00

    The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.

  • CVE-2003-1357Dec 31, 2003
    risk 0.00cvss epss 0.02

    ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.

  • CVE-2003-1358Dec 31, 2003
    risk 0.03cvss epss 0.01

    rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.

  • CVE-2003-1359Dec 31, 2003
    risk 0.03cvss epss 0.01

    Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.

  • CVE-2003-1360Dec 31, 2003
    risk 0.00cvss epss 0.01

    Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.

  • CVE-2003-1361Dec 31, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.

  • CVE-2003-1362Dec 31, 2003
    risk 0.00cvss epss 0.02

    Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.

  • CVE-2003-1363Dec 31, 2003
    risk 0.00cvss epss 0.01

    The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.

  • CVE-2003-1364Dec 31, 2003
    risk 0.04cvss epss 0.08

    Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.

  • CVE-2003-1365Dec 31, 2003
    risk 0.00cvss epss 0.02

    The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write…

  • CVE-2003-1366Dec 31, 2003
    risk 0.03cvss epss 0.01

    chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.