VYPR

CVEs

377,915 total · page 7420 of 7,559

  • CVE-2003-0408Jun 30, 2003
    risk 0.03cvss epss 0.01

    Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.

  • CVE-2003-0409Jun 30, 2003
    risk 0.04cvss epss 0.08

    Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.

  • CVE-2003-0410Jun 30, 2003
    risk 0.01cvss epss 0.07

    Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.

  • CVE-2003-0411HigJun 30, 2003
    risk 0.54cvss 7.5epss 0.25

    Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.

  • CVE-2003-0412Jun 30, 2003
    risk 0.00cvss epss 0.02

    Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.

  • CVE-2003-0413Jun 30, 2003
    risk 0.04cvss epss 0.07

    Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an…

  • CVE-2003-0414Jun 30, 2003
    risk 0.00cvss epss 0.00

    The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.

  • CVE-2003-0415Jun 30, 2003
    risk 0.00cvss epss 0.02

    Remote PC Access Server 2.2 allows remote attackers to cause a denial of service (crash) by receiving packets from the server and sending them back to the server.

  • CVE-2003-0416Jun 30, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.

  • CVE-2003-0417Jun 30, 2003
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Son hServer 0.2 allows remote attackers to read arbitrary files via ".|." (modified dot-dot) sequences.

  • CVE-2003-1067Jun 19, 2003
    risk 0.00cvss epss 0.00

    Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.

  • CVE-2003-1086Jun 17, 2003
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.

  • CVE-2002-1155Jun 16, 2003
    risk 0.03cvss epss 0.01

    Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.

  • CVE-2002-1565Jun 16, 2003
    risk 0.00cvss epss 0.03

    Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.

  • CVE-2003-0195Jun 16, 2003
    risk 0.04cvss epss 0.11

    CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.

  • CVE-2003-0217Jun 16, 2003
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.

  • CVE-2003-0246Jun 16, 2003
    risk 0.00cvss epss 0.01

    The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.

  • CVE-2003-0247Jun 16, 2003
    risk 0.00cvss epss 0.03

    Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").

  • CVE-2003-0248Jun 16, 2003
    risk 0.00cvss epss 0.04

    The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.

  • CVE-2003-0270Jun 16, 2003
    risk 0.04cvss epss 0.11

    The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is…

  • CVE-2003-0275Jun 16, 2003
    risk 0.00cvss epss 0.01

    SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.

  • CVE-2003-0276Jun 16, 2003
    risk 0.04cvss epss 0.11

    Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.

  • CVE-2003-0277Jun 16, 2003
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.

  • CVE-2003-0278Jun 16, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

  • CVE-2003-0279Jun 16, 2003
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.

  • CVE-2003-0280Jun 16, 2003
    risk 0.04cvss epss 0.15

    Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.

  • CVE-2003-0281Jun 16, 2003
    risk 0.03cvss epss 0.01

    Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3)…

  • CVE-2003-0282Jun 16, 2003
    risk 0.05cvss epss 0.22

    Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.

  • CVE-2003-0283Jun 16, 2003
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

  • CVE-2003-0284Jun 16, 2003
    risk 0.00cvss epss 0.02

    Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.

  • CVE-2003-0285Jun 16, 2003
    risk 0.00cvss epss 0.05

    IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam…

  • CVE-2003-0286Jun 16, 2003
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.

  • CVE-2003-0287Jun 16, 2003
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled.

  • CVE-2003-0288Jun 16, 2003
    risk 0.00cvss epss 0.05

    Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.

  • CVE-2003-0289Jun 16, 2003
    risk 0.03cvss epss 0.01

    Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

  • CVE-2003-0290Jun 16, 2003
    risk 0.04cvss epss 0.08

    Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.

  • CVE-2003-0291Jun 16, 2003
    risk 0.00cvss epss 0.02

    3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.

  • CVE-2003-0292Jun 16, 2003
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka "Man-in-the-Middle" XSS.

  • CVE-2003-0293Jun 16, 2003
    risk 0.03cvss epss 0.05

    PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.

  • CVE-2003-0294Jun 16, 2003
    risk 0.00cvss epss 0.01

    autohtml.php in php-proxima 6.0 and earlier allows remote attackers to read arbitrary files via the name parameter in a modload operation.

  • CVE-2003-0295Jun 16, 2003
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.

  • CVE-2003-0296Jun 16, 2003
    risk 0.00cvss epss 0.02

    The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.

  • CVE-2003-0297Jun 16, 2003
    risk 0.00cvss epss 0.03

    c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or…

  • CVE-2003-0298Jun 16, 2003
    risk 0.00cvss epss 0.02

    The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow…

  • CVE-2003-0299Jun 16, 2003
    risk 0.00cvss epss 0.02

    The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer overflow errors.

  • CVE-2003-0300Jun 16, 2003
    risk 0.00cvss epss 0.03

    The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.

  • CVE-2003-0301Jun 16, 2003
    risk 0.00cvss epss 0.06

    The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.

  • CVE-2003-0302Jun 16, 2003
    risk 0.00cvss epss 0.01

    The IMAP Client for Eudora 5.2.1 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.

  • CVE-2003-0310Jun 16, 2003
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

  • CVE-2003-0312Jun 16, 2003
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.