VYPR

CVEs

378,128 total · page 7414 of 7,563

  • CVE-2003-0960Dec 15, 2003
    risk 0.00cvss epss 0.01

    OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.

  • CVE-2003-0961Dec 15, 2003
    risk 0.03cvss epss 0.03

    Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.

  • CVE-2003-0962Dec 15, 2003
    risk 0.02cvss epss 0.21

    Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.

  • CVE-2003-0967Dec 15, 2003
    risk 0.03cvss epss 0.05

    rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.

  • CVE-2003-0968Dec 15, 2003
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute.

  • CVE-2003-0970Dec 15, 2003
    risk 0.00cvss epss 0.01

    The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporarily disabled.

  • CVE-2003-0971Dec 15, 2003
    risk 0.00cvss epss 0.03

    GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.

  • CVE-2003-0972Dec 15, 2003
    risk 0.00cvss epss 0.03

    Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.

  • CVE-2003-0973Dec 15, 2003
    risk 0.00cvss epss 0.06

    Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.

  • CVE-2003-0974Dec 15, 2003
    risk 0.03cvss epss 0.03

    Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console, as demonstrated using appliedsnatch.c, or (2) add spurious IDS rules to sensors, as demonstrated using addrule.c.

  • CVE-2003-0975Dec 15, 2003
    risk 0.00cvss epss 0.01

    Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.

  • CVE-2003-0976Dec 15, 2003
    risk 0.00cvss epss 0.01

    NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.

  • CVE-2003-1056Dec 11, 2003
    risk 0.00cvss epss 0.00

    The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2003-1057Dec 8, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.

  • CVE-2003-1058Dec 3, 2003
    risk 0.00cvss epss 0.00

    The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on temporary server files.

  • CVE-2003-0564Dec 1, 2003
    risk 0.01cvss epss 0.09

    Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected…

  • CVE-2003-0565Dec 1, 2003
    risk 0.00cvss epss 0.03

    Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test…

  • CVE-2003-0621Dec 1, 2003
    risk 0.04cvss epss 0.08

    The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.

  • CVE-2003-0622Dec 1, 2003
    risk 0.00cvss epss 0.02

    The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.

  • CVE-2003-0623Dec 1, 2003
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.

  • CVE-2003-0624Dec 1, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.

  • CVE-2003-0788Dec 1, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).

  • CVE-2003-0834Dec 1, 2003
    risk 0.03cvss epss 0.01

    Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.

  • CVE-2003-0851Dec 1, 2003
    risk 0.00cvss epss 0.06

    OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.

  • CVE-2003-0886Dec 1, 2003
    risk 0.04cvss epss 0.12

    Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.

  • CVE-2003-0913Dec 1, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the Terminal application for Mac OS X 10.3 (Client and Server) may allow "unauthorized access."

  • CVE-2003-0925Dec 1, 2003
    risk 0.00cvss epss 0.06

    Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.

  • CVE-2003-0926Dec 1, 2003
    risk 0.00cvss epss 0.04

    Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.

  • CVE-2003-0927Dec 1, 2003
    risk 0.00cvss epss 0.06

    Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.

  • CVE-2003-0933Dec 1, 2003
    risk 0.00cvss epss 0.00

    Buffer overflow in conquest 7.2 and earlier may allow a local user to execute arbitrary code via a long environment variable.

  • CVE-2003-0934Dec 1, 2003
    risk 0.00cvss epss 0.00

    Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.

  • CVE-2003-0935Dec 1, 2003
    risk 0.00cvss epss 0.01

    Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.

  • CVE-2003-1216Nov 27, 2003
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.

  • CVE-2003-1084Nov 24, 2003
    risk 0.00cvss epss 0.04

    Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.

  • CVE-2003-1195Nov 23, 2003
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable.

  • CVE-2003-1059Nov 20, 2003
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.

  • CVE-2001-1411Nov 17, 2003
    risk 0.00cvss epss 0.00

    Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.

  • CVE-2001-1412Nov 17, 2003
    risk 0.03cvss epss 0.01

    nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.

  • CVE-2002-1568Nov 17, 2003
    risk 0.00cvss epss 0.03

    OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2…

  • CVE-2002-1569Nov 17, 2003
    risk 0.00cvss epss 0.02

    gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file.

  • CVE-2003-0543Nov 17, 2003
    risk 0.05cvss epss 0.27

    Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.

  • CVE-2003-0544Nov 17, 2003
    risk 0.01cvss epss 0.07

    OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.

  • CVE-2003-0545CriNov 17, 2003
    risk 0.71cvss 9.8epss 0.88

    Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.

  • CVE-2003-0659Nov 17, 2003
    risk 0.06cvss epss 0.43

    Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.

  • CVE-2003-0660Nov 17, 2003
    risk 0.02cvss epss 0.24

    The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.

  • CVE-2003-0662Nov 17, 2003
    risk 0.03cvss epss 0.38

    Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.

  • CVE-2003-0711Nov 17, 2003
    risk 0.03cvss epss 0.37

    Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.

  • CVE-2003-0712Nov 17, 2003
    risk 0.02cvss epss 0.20

    Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.

  • CVE-2003-0714Nov 17, 2003
    risk 0.09cvss epss 0.78

    The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange…

  • CVE-2003-0717Nov 17, 2003
    risk 0.08cvss epss 0.61

    The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.