| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2003-0748 | 0.04 | — | 0.08 | Oct 20, 2003 | Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space… | |||
| CVE-2003-0749 | 0.03 | — | 0.04 | Oct 20, 2003 | Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter. | |||
| CVE-2003-0750 | 0.00 | — | 0.02 | Oct 20, 2003 | secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter. | |||
| CVE-2003-0751 | 0.00 | — | 0.01 | Oct 20, 2003 | SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter. | |||
| CVE-2003-0752 | 0.03 | — | 0.01 | Oct 20, 2003 | SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter. | |||
| CVE-2003-0753 | 0.00 | — | 0.02 | Oct 20, 2003 | nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter. | |||
| CVE-2003-0754 | 0.00 | — | 0.02 | Oct 20, 2003 | nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication. | |||
| CVE-2003-0755 | 0.04 | — | 0.06 | Oct 20, 2003 | Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command. | |||
| CVE-2003-0756 | 0.00 | — | 0.02 | Oct 20, 2003 | Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter. | |||
| CVE-2003-0757 | 0.03 | — | 0.03 | Oct 20, 2003 | Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet. | |||
| CVE-2003-1062 | 0.00 | — | 0.00 | Oct 15, 2003 | Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory. | |||
| CVE-2003-1061 | 0.00 | — | 0.00 | Oct 14, 2003 | Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines. | |||
| CVE-2003-0791 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2003 | The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed. | ||
| CVE-2002-1567 | 0.05 | — | 0.27 | Oct 6, 2003 | Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script. | |||
| CVE-2003-0680 | 0.00 | — | 0.01 | Oct 6, 2003 | Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions. | |||
| CVE-2003-0681 | 0.05 | — | 0.22 | Oct 6, 2003 | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences. | |||
| CVE-2003-0682 | 0.01 | — | 0.09 | Oct 6, 2003 | "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695. | |||
| CVE-2003-0690 | 0.00 | — | 0.03 | Oct 6, 2003 | KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module. | |||
| CVE-2003-0692 | 0.00 | — | 0.03 | Oct 6, 2003 | KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session. | |||
| CVE-2003-0694 | 0.08 | — | 0.66 | Oct 6, 2003 | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | |||
| CVE-2003-0695 | 0.00 | — | 0.04 | Oct 6, 2003 | Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than… | |||
| CVE-2003-0697 | 0.00 | — | 0.00 | Oct 6, 2003 | Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges. | |||
| CVE-2003-0742 | 0.00 | — | 0.00 | Oct 6, 2003 | SCO Internet Manager (mana) allows local users to execute arbitrary programs by setting the REMOTE_ADDR environment variable to cause menu.mana to run as if it were called from ncsa_httpd, then modifying the PATH environment variable to point to a malicious "hostname" program. | |||
| CVE-2003-0758 | 0.03 | — | 0.01 | Oct 6, 2003 | Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument. | |||
| CVE-2003-0759 | 0.03 | — | 0.01 | Oct 6, 2003 | Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument. | |||
| CVE-2003-0783 | 0.03 | — | 0.01 | Oct 6, 2003 | Multiple buffer overflows in hztty 2.0 allow local users to gain root privileges. | |||
| CVE-2003-0784 | 0.00 | — | 0.02 | Oct 6, 2003 | Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers. | |||
| CVE-2003-0785 | 0.00 | — | 0.02 | Oct 6, 2003 | ipmasq before 3.5.12, in certain configurations, may forward packets to the external interface even if the packets are not associated with an established connection, which could allow remote attackers to bypass intended filtering. | |||
| CVE-2003-0801 | 0.04 | — | 0.12 | Oct 6, 2003 | Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script. | |||
| CVE-2003-0802 | 0.04 | — | 0.07 | Oct 6, 2003 | Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot). | |||
| CVE-2003-0803 | 0.03 | — | 0.06 | Oct 6, 2003 | Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user. | |||
| CVE-2003-0805 | 0.03 | — | 0.05 | Oct 6, 2003 | Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type. | |||
| CVE-2003-0826 | 0.04 | — | 0.12 | Oct 6, 2003 | lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack. | |||
| CVE-2003-0827 | 0.00 | — | 0.01 | Oct 6, 2003 | The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523. | |||
| CVE-2003-1053 | 0.00 | — | 0.01 | Oct 3, 2003 | Multiple buffer overflows in XShisen allow attackers to execute arbitrary code via a long (1) -KCONV command line option or (2) XSHISENLIB environment variable. | |||
| CVE-2003-0693 | 0.00 | — | 0.11 | Sep 22, 2003 | A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695. | |||
| CVE-2003-0722 | 0.10 | — | 0.89 | Sep 22, 2003 | The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets. | |||
| CVE-2003-0768 | 0.01 | — | 0.13 | Sep 22, 2003 | Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name. | |||
| CVE-2003-0769 | 0.03 | — | 0.04 | Sep 22, 2003 | Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field. | |||
| CVE-2003-0770 | 0.04 | — | 0.11 | Sep 22, 2003 | FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement. | |||
| CVE-2003-0771 | 0.00 | — | 0.00 | Sep 22, 2003 | Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does. | |||
| CVE-2003-0772 | 0.10 | — | 0.85 | Sep 22, 2003 | Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments. | |||
| CVE-2003-0773 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf. | |||
| CVE-2003-0774 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed. | |||
| CVE-2003-0775 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash). | |||
| CVE-2003-0776 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences. | |||
| CVE-2003-0777 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault). | |||
| CVE-2003-0778 | 0.00 | — | 0.02 | Sep 22, 2003 | saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption). | |||
| CVE-2003-0779 | 0.00 | — | 0.01 | Sep 22, 2003 | SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string. | |||
| CVE-2003-0780 | 0.09 | — | 0.78 | Sep 22, 2003 | Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field. |
- CVE-2003-0748Oct 20, 2003risk 0.04cvss —epss 0.08
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space…
- CVE-2003-0749Oct 20, 2003risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.
- CVE-2003-0750Oct 20, 2003risk 0.00cvss —epss 0.02
secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.
- CVE-2003-0751Oct 20, 2003risk 0.00cvss —epss 0.01
SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.
- CVE-2003-0752Oct 20, 2003risk 0.03cvss —epss 0.01
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.
- CVE-2003-0753Oct 20, 2003risk 0.00cvss —epss 0.02
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.
- CVE-2003-0754Oct 20, 2003risk 0.00cvss —epss 0.02
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
- CVE-2003-0755Oct 20, 2003risk 0.04cvss —epss 0.06
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.
- CVE-2003-0756Oct 20, 2003risk 0.00cvss —epss 0.02
Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.
- CVE-2003-0757Oct 20, 2003risk 0.03cvss —epss 0.03
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.
- CVE-2003-1062Oct 15, 2003risk 0.00cvss —epss 0.00
Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.
- CVE-2003-1061Oct 14, 2003risk 0.00cvss —epss 0.00
Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.
- risk 0.64cvss 9.8epss 0.02
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
- CVE-2002-1567Oct 6, 2003risk 0.05cvss —epss 0.27
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
- CVE-2003-0680Oct 6, 2003risk 0.00cvss —epss 0.01
Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.
- CVE-2003-0681Oct 6, 2003risk 0.05cvss —epss 0.22
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
- CVE-2003-0682Oct 6, 2003risk 0.01cvss —epss 0.09
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.
- CVE-2003-0690Oct 6, 2003risk 0.00cvss —epss 0.03
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
- CVE-2003-0692Oct 6, 2003risk 0.00cvss —epss 0.03
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.
- CVE-2003-0694Oct 6, 2003risk 0.08cvss —epss 0.66
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
- CVE-2003-0695Oct 6, 2003risk 0.00cvss —epss 0.04
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than…
- CVE-2003-0697Oct 6, 2003risk 0.00cvss —epss 0.00
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
- CVE-2003-0742Oct 6, 2003risk 0.00cvss —epss 0.00
SCO Internet Manager (mana) allows local users to execute arbitrary programs by setting the REMOTE_ADDR environment variable to cause menu.mana to run as if it were called from ncsa_httpd, then modifying the PATH environment variable to point to a malicious "hostname" program.
- CVE-2003-0758Oct 6, 2003risk 0.03cvss —epss 0.01
Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.
- CVE-2003-0759Oct 6, 2003risk 0.03cvss —epss 0.01
Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.
- CVE-2003-0783Oct 6, 2003risk 0.03cvss —epss 0.01
Multiple buffer overflows in hztty 2.0 allow local users to gain root privileges.
- CVE-2003-0784Oct 6, 2003risk 0.00cvss —epss 0.02
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.
- CVE-2003-0785Oct 6, 2003risk 0.00cvss —epss 0.02
ipmasq before 3.5.12, in certain configurations, may forward packets to the external interface even if the packets are not associated with an established connection, which could allow remote attackers to bypass intended filtering.
- CVE-2003-0801Oct 6, 2003risk 0.04cvss —epss 0.12
Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.
- CVE-2003-0802Oct 6, 2003risk 0.04cvss —epss 0.07
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).
- CVE-2003-0803Oct 6, 2003risk 0.03cvss —epss 0.06
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.
- CVE-2003-0805Oct 6, 2003risk 0.03cvss —epss 0.05
Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.
- CVE-2003-0826Oct 6, 2003risk 0.04cvss —epss 0.12
lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.
- CVE-2003-0827Oct 6, 2003risk 0.00cvss —epss 0.01
The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.
- CVE-2003-1053Oct 3, 2003risk 0.00cvss —epss 0.01
Multiple buffer overflows in XShisen allow attackers to execute arbitrary code via a long (1) -KCONV command line option or (2) XSHISENLIB environment variable.
- CVE-2003-0693Sep 22, 2003risk 0.00cvss —epss 0.11
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.
- CVE-2003-0722Sep 22, 2003risk 0.10cvss —epss 0.89
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.
- CVE-2003-0768Sep 22, 2003risk 0.01cvss —epss 0.13
Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.
- CVE-2003-0769Sep 22, 2003risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.
- CVE-2003-0770Sep 22, 2003risk 0.04cvss —epss 0.11
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.
- CVE-2003-0771Sep 22, 2003risk 0.00cvss —epss 0.00
Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.
- CVE-2003-0772Sep 22, 2003risk 0.10cvss —epss 0.85
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.
- CVE-2003-0773Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.
- CVE-2003-0774Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.
- CVE-2003-0775Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).
- CVE-2003-0776Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.
- CVE-2003-0777Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).
- CVE-2003-0778Sep 22, 2003risk 0.00cvss —epss 0.02
saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).
- CVE-2003-0779Sep 22, 2003risk 0.00cvss —epss 0.01
SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.
- CVE-2003-0780Sep 22, 2003risk 0.09cvss —epss 0.78
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.