Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2003-0474 | 1 Ashley Brown | 1 Iweb Server | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475. | |||||
CVE-2003-0475 | 1 Ashley Brown | 1 Iweb Server | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474. | |||||
CVE-2003-0477 | 1 Wzdftpd | 1 Wzdftpd | 2016-10-17 | 5.0 MEDIUM | N/A |
wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument. | |||||
CVE-2003-0478 | 5 Andromede, Bahamut, Daniel Moss and 2 more | 5 Adromedeircd, Ircd, Methane and 2 more | 2016-10-17 | 10.0 HIGH | N/A |
Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings. | |||||
CVE-2003-0479 | 1 Affordable Web Space Design | 1 Affordable Web Space Design Webbbs | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS allows remote attackers to insert arbitrary web script via the (1) Name, (2) Email, or (3) Message fields. | |||||
CVE-2003-0480 | 1 Vmware | 1 Workstation | 2016-10-17 | 3.7 LOW | N/A |
VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation." | |||||
CVE-2003-0481 | 1 Gero Kohnert | 1 Tutos | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php. | |||||
CVE-2003-0482 | 1 Gero Kohnert | 1 Tutos | 2016-10-17 | 7.5 HIGH | N/A |
TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code. | |||||
CVE-2003-0484 | 1 Phpbb Group | 1 Phpbb | 2016-10-17 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter. | |||||
CVE-2003-0485 | 1 Progress | 1 4gl Compiler | 2016-10-17 | 4.6 MEDIUM | N/A |
Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type. | |||||
CVE-2003-0490 | 1 Dantz | 1 Retrospect Client | 2016-10-17 | 7.2 HIGH | N/A |
The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code. | |||||
CVE-2003-0491 | 1 Mytutorials | 1 Tutorials | 2016-10-17 | 7.5 HIGH | N/A |
The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file. | |||||
CVE-2003-0493 | 1 Snitz Communications | 1 Snitz Forums 2000 | 2016-10-17 | 10.0 HIGH | N/A |
Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID. | |||||
CVE-2003-0503 | 1 Microsoft | 1 Windows 2000 | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument. | |||||
CVE-2003-0504 | 1 Phpgroupware | 1 Phpgroupware | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module. | |||||
CVE-2003-0505 | 1 Microsoft | 1 Netmeeting | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request. | |||||
CVE-2003-0506 | 1 Microsoft | 1 Netmeeting | 2016-10-17 | 5.0 MEDIUM | N/A |
Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation. | |||||
CVE-2003-0507 | 1 Microsoft | 1 Windows 2000 | 2016-10-17 | 7.5 HIGH | N/A |
Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR," and possibly other statements, which causes LSASS.EXE to crash. | |||||
CVE-2003-0508 | 1 Adobe | 1 Acrobat Reader | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link. | |||||
CVE-2003-0510 | 1 Ezbounce | 1 Ezbounce | 2016-10-17 | 7.5 HIGH | N/A |
Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command. |