|
313751
|
7.2 |
HIGH
|
sco
|
openserver
|
Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.
|
NVD-CWE-Other
|
CVE-2004-0510
|
2024-02-14 10:17 |
2004-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313752
|
5.0 |
MEDIUM
|
ethereal_group conectiva sgi redhat suse debian altlinux
|
ethereal linux propack enterprise_linux suse_linux enterprise_linux_desktop debian_linux linux_advanced_workstation alt_linux
|
Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).
|
NVD-CWE-Other
|
CVE-2004-1139
|
2024-02-14 10:17 |
2004-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313753
|
5.0 |
MEDIUM
|
ethereal_group conectiva sgi redhat suse debian altlinux
|
ethereal linux propack enterprise_linux suse_linux enterprise_linux_desktop debian_linux linux_advanced_workstation alt_linux
|
Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.
|
NVD-CWE-Other
|
CVE-2004-1142
|
2024-02-14 10:17 |
2004-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313754
|
2.1 |
LOW
|
linux redhat
|
linux_kernel fedora_core linux
|
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a …
|
NVD-CWE-Other
|
CVE-2004-1333
|
2024-02-14 10:17 |
2004-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313755
|
2.1 |
LOW
|
-
|
-
|
Integer overflow in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (kernel crash) via a cmsg_len that contains a -1, which leads to a bu…
|
NVD-CWE-Other
|
CVE-2004-1334
|
2024-02-14 10:17 |
2004-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313756
|
2.1 |
LOW
|
linux redhat
|
linux_kernel fedora_core linux
|
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.
|
NVD-CWE-Other
|
CVE-2004-1335
|
2024-02-14 10:17 |
2004-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313757
|
5.0 |
MEDIUM
|
ethereal_group redhat mandrakesoft gentoo
|
ethereal enterprise_linux linux_advanced_workstation mandrake_linux linux
|
The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.
|
NVD-CWE-Other
|
CVE-2004-0633
|
2024-02-14 10:17 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313758
|
5.0 |
MEDIUM
|
ethereal_group redhat mandrakesoft gentoo
|
ethereal enterprise_linux linux_advanced_workstation mandrake_linux linux
|
The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.
|
NVD-CWE-Other
|
CVE-2004-0634
|
2024-02-14 10:17 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313759
|
5.0 |
MEDIUM
|
ethereal_group redhat mandrakesoft gentoo
|
ethereal enterprise_linux linux_advanced_workstation mandrake_linux linux
|
The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-b…
|
NVD-CWE-Other
|
CVE-2004-0635
|
2024-02-14 10:17 |
2004-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313760
|
2.1 |
LOW
|
broadcom
|
inoculateit
|
The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to overwrite arbitrary files via a symlink attack on files in /tmp.
|
NVD-CWE-Other
|
CVE-2004-0267
|
2024-02-14 10:17 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313761
|
5.0 |
MEDIUM
|
pgina
|
pgina
|
pGina 1.7.6 and possibly older versions, when the Restart or Shutdown options are enabled on the login screen, allows remote attackers to cause a denial of service by connecting via Remote Desktop an…
|
NVD-CWE-Other
|
CVE-2004-1625
|
2024-02-14 10:17 |
2004-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313762
|
4.3 |
MEDIUM
|
web_animations
|
password_protect
|
Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script…
|
NVD-CWE-Other
|
CVE-2004-1648
|
2024-02-14 10:17 |
2004-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313763
|
7.5 |
HIGH
|
web_animations
|
password_protect
|
SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, O…
|
NVD-CWE-Other
|
CVE-2004-1647
|
2024-02-14 10:17 |
2004-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313764
|
5.0 |
MEDIUM
|
ethereal_group sgi
|
ethereal propack
|
Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.
|
NVD-CWE-Other
|
CVE-2004-0504
|
2024-02-14 10:17 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313765
|
5.0 |
MEDIUM
|
ethereal_group sgi
|
ethereal propack
|
The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2004-0505
|
2024-02-14 10:17 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313766
|
5.0 |
MEDIUM
|
ethereal_group sgi
|
ethereal propack
|
The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.
|
NVD-CWE-Other
|
CVE-2004-0506
|
2024-02-14 10:17 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313767
|
10.0 |
HIGH
|
ethereal_group sgi
|
ethereal propack
|
Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0507
|
2024-02-14 10:17 |
2004-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313768
|
10.0 |
HIGH
|
fastream
|
netfile_ftp_web_server
|
Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequence…
|
NVD-CWE-Other
|
CVE-2004-0676
|
2024-02-14 10:17 |
2004-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313769
|
4.6 |
MEDIUM
|
openbsd
|
openbsd
|
Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow …
|
NVD-CWE-Other
|
CVE-2004-0482
|
2024-02-14 10:17 |
2004-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313770
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) I…
|
NVD-CWE-Other
|
CVE-2004-0176
|
2024-02-14 10:17 |
2004-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313771
|
7.5 |
HIGH
Network
|
ethereal
|
ethereal
|
The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a …
|
CWE-476
NULL Pointer Dereference
|
CVE-2004-0365
|
2024-02-14 10:17 |
2004-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313772
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.
|
NVD-CWE-Other
|
CVE-2004-0367
|
2024-02-14 10:17 |
2004-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313773
|
10.0 |
HIGH
|
washington_university
|
wu-ftpd
|
Buffer overflow in the skey_challenge function in ftpd.c for wu-ftp daemon (wu-ftpd) 2.6.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a s/key (SKEY) …
|
NVD-CWE-Other
|
CVE-2004-0185
|
2024-02-14 10:17 |
2004-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313774
|
4.6 |
MEDIUM
|
broadcom
|
inoculateit
|
eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or…
|
NVD-CWE-Other
|
CVE-2004-2092
|
2024-02-14 10:17 |
2004-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313775
|
4.6 |
MEDIUM
|
ibm
|
lotus_domino
|
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
|
NVD-CWE-Other
|
CVE-2004-0029
|
2024-02-14 10:17 |
2004-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313776
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.
|
NVD-CWE-Other
|
CVE-2003-1012
|
2024-02-14 10:17 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313777
|
7.5 |
HIGH
Network
|
ethereal
|
ethereal
|
The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2003-1013
|
2024-02-14 10:17 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313778
|
10.0 |
HIGH
|
aol
|
instant_messenger
|
Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2003-1503
|
2024-02-14 10:17 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313779
|
4.6 |
MEDIUM
|
sco
|
unixware open_unix
|
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and c…
|
NVD-CWE-Other
|
CVE-2003-0937
|
2024-02-14 10:17 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313780
|
7.5 |
HIGH
|
ethereal_group
|
ethereal
|
Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.
|
NVD-CWE-Other
|
CVE-2003-0925
|
2024-02-14 10:17 |
2003-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313781
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.
|
NVD-CWE-Other
|
CVE-2003-0926
|
2024-02-14 10:17 |
2003-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313782
|
7.5 |
HIGH
|
ethereal_group
|
ethereal
|
Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.
|
NVD-CWE-Other
|
CVE-2003-0927
|
2024-02-14 10:17 |
2003-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313783
|
9.8 |
CRITICAL
Network
|
acme
|
thttpd
|
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when th…
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2003-0899
|
2024-02-14 10:17 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313784
|
6.8 |
MEDIUM
|
phpkit
|
phpkit
|
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.
|
NVD-CWE-Other
|
CVE-2003-1187
|
2024-02-14 10:17 |
2003-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313785
|
5.1 |
MEDIUM
|
realnetworks
|
realone_desktop_manager realone_player realone_enterprise_desktop
|
RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security…
|
NVD-CWE-Other
|
CVE-2003-0726
|
2024-02-14 10:17 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313786
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.
|
NVD-CWE-Other
|
CVE-2003-0428
|
2024-02-14 10:17 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313787
|
7.5 |
HIGH
|
ethereal_group
|
ethereal
|
The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering …
|
NVD-CWE-Other
|
CVE-2003-0429
|
2024-02-14 10:17 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313788
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.
|
NVD-CWE-Other
|
CVE-2003-0430
|
2024-02-14 10:17 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313789
|
10.0 |
HIGH
|
ethereal_group
|
ethereal
|
The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.
|
NVD-CWE-Other
|
CVE-2003-0431
|
2024-02-14 10:17 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313790
|
10.0 |
HIGH
|
ethereal_group
|
ethereal
|
Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dis…
|
NVD-CWE-Other
|
CVE-2003-0432
|
2024-02-14 10:17 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313791
|
7.5 |
HIGH
|
ethereal_group
|
ethereal
|
Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissecto…
|
NVD-CWE-Other
|
CVE-2003-0357
|
2024-02-14 10:17 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313792
|
10.0 |
HIGH
|
miniportal
|
miniportal
|
admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.
|
NVD-CWE-Other
|
CVE-2003-0272
|
2024-02-14 10:17 |
2003-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313793
|
7.5 |
HIGH
|
battleaxe_software
|
bttlxeforum
|
SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.
|
NVD-CWE-Other
|
CVE-2003-0215
|
2024-02-14 10:17 |
2003-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313794
|
7.5 |
HIGH
|
the_cacti_group
|
cacti
|
graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.
|
NVD-CWE-Other
|
CVE-2002-1477
|
2024-02-14 10:17 |
2003-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313795
|
10.0 |
HIGH
|
the_cacti_group
|
cacti
|
Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.
|
NVD-CWE-Other
|
CVE-2002-1478
|
2024-02-14 10:17 |
2003-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313796
|
4.6 |
MEDIUM
|
the_cacti_group
|
cacti
|
Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly g…
|
NVD-CWE-Other
|
CVE-2002-1479
|
2024-02-14 10:17 |
2003-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313797
|
5.0 |
MEDIUM
|
endity.com
|
shoutbox
|
Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter.
|
NVD-CWE-Other
|
CVE-2002-1429
|
2024-02-14 10:17 |
2003-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313798
|
7.5 |
HIGH
|
ethereal_group
|
ethereal
|
Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0159
|
2024-02-14 10:17 |
2003-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313799
|
7.5 |
HIGH
|
ethereal_group
|
ethereal
|
Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string spec…
|
NVD-CWE-Other
|
CVE-2003-0081
|
2024-02-14 10:17 |
2003-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313800
|
5.0 |
MEDIUM
|
pingtel
|
xpressa
|
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of the Admin password, MD5 hash of the phys…
|
NVD-CWE-Other
|
CVE-2002-1934
|
2024-02-14 10:17 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|