Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2003-0562 | 1 Novell | 1 Netware | 2016-10-17 | 5.0 MEDIUM | N/A |
Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string. | |||||
CVE-2003-0578 | 1 Ibm | 1 U2 Universe | 2016-10-17 | 4.6 MEDIUM | N/A |
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files. | |||||
CVE-2003-0579 | 1 Ibm | 1 U2 Universe | 2016-10-17 | 4.6 MEDIUM | N/A |
uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user. | |||||
CVE-2003-0580 | 1 Ibm | 1 U2 Universe | 2016-10-17 | 7.2 HIGH | N/A |
Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument. | |||||
CVE-2003-0581 | 1 Xfstt | 1 Xfstt | 2016-10-17 | 7.5 HIGH | N/A |
X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges value, which causes an out-of-bounds array access. | |||||
CVE-2003-0583 | 1 Tolis Group | 1 Bru | 2016-10-17 | 7.2 HIGH | N/A |
Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument. | |||||
CVE-2003-0584 | 1 Tolis Group | 1 Bru | 2016-10-17 | 7.2 HIGH | N/A |
Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument. | |||||
CVE-2003-0585 | 1 Brooky | 1 Estore | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters. | |||||
CVE-2003-0586 | 1 Brooky | 1 Estore | 2016-10-17 | 7.5 HIGH | N/A |
Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php. | |||||
CVE-2003-0587 | 1 Infopop | 1 Ultimate Bulletin Board | 2016-10-17 | 6.9 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie. | |||||
CVE-2003-0588 | 1 Digi-fx | 1 Digi-news | 2016-10-17 | 10.0 HIGH | N/A |
admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password. | |||||
CVE-2003-0589 | 1 Digi-fx | 1 Digi-news | 2016-10-17 | 10.0 HIGH | N/A |
admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password. | |||||
CVE-2003-0590 | 1 Splatt | 1 Splatt Forum | 2016-10-17 | 7.1 HIGH | N/A |
Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field. | |||||
CVE-2003-0597 | 1 Sco | 1 Openserver | 2016-10-17 | 7.2 HIGH | N/A |
Unknown vulnerability in display of Merge before 5.3.23a in UnixWare 7.1.x allows local users to gain root privileges. | |||||
CVE-2003-0617 | 1 Hugo Rabson | 1 Mindi | 2016-10-17 | 4.6 MEDIUM | N/A |
mindi 0.58 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files. | |||||
CVE-2003-0620 | 1 Andries Brouwer | 1 Man | 2016-10-17 | 4.6 MEDIUM | N/A |
Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable. | |||||
CVE-2003-0453 | 1 Ehud Gavron | 1 Traceroute-nanog | 2016-10-17 | 10.0 HIGH | N/A |
traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow. | |||||
CVE-2003-0455 | 1 Imagemagick | 1 Libmagick Library | 2016-10-17 | 4.6 MEDIUM | N/A |
The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files. | |||||
CVE-2003-0467 | 1 Linux | 1 Linux Kernel | 2016-10-17 | 5.0 MEDIUM | N/A |
Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC is enabled, or the ip_nat_ftp or ip_nat_irc modules are loaded, allows remote attackers to cause a denial of service (crash) in systems using NAT, possibly due to an integer signedness error. | |||||
CVE-2003-0471 | 1 Alt-n | 1 Webadmin | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument. |