|
345001
|
5.0 |
MEDIUM
|
microsoft
|
ie
|
Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup window and disables the imagetoolbar functionality with a META tag, which trig…
|
NVD-CWE-Other
|
CVE-2004-0479
|
2016-10-18 11:45 |
2004-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345002
|
6.4 |
MEDIUM
|
yabb
|
yabb
|
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.
|
NVD-CWE-Other
|
CVE-2004-0344
|
2016-10-18 11:44 |
2004-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345003
|
5.0 |
MEDIUM
|
lionmax_software
|
www_file_share_pro
|
Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter…
|
NVD-CWE-Other
|
CVE-2004-0059
|
2016-10-18 11:40 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345004
|
5.0 |
MEDIUM
|
lionmax_software
|
www_file_share_pro
|
WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.
|
NVD-CWE-Other
|
CVE-2004-0060
|
2016-10-18 11:40 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345005
|
7.5 |
HIGH
|
lionmax_software
|
www_file_share_pro
|
WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.
|
NVD-CWE-Other
|
CVE-2004-0061
|
2016-10-18 11:40 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345006
|
7.5 |
HIGH
|
fishnet
|
fishcart
|
Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.
|
NVD-CWE-Other
|
CVE-2004-0062
|
2016-10-18 11:40 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345007
|
2.1 |
LOW
|
suse
|
suse_linux
|
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary …
|
NVD-CWE-Other
|
CVE-2004-0064
|
2016-10-18 11:40 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345008
|
7.5 |
HIGH
|
phpgedview
|
phpgedview
|
Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.
|
NVD-CWE-Other
|
CVE-2004-0065
|
2016-10-18 11:40 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345009
|
7.5 |
HIGH
|
hd_soft
|
windows_ftp_server
|
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wsc…
|
NVD-CWE-Other
|
CVE-2004-0069
|
2016-10-18 11:40 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345010
|
7.5 |
HIGH
|
pmachine
|
pmachine_free pmachine_pro
|
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to r…
|
NVD-CWE-Other
|
CVE-2003-1086
|
2016-10-18 11:39 |
2003-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345011
|
6.4 |
MEDIUM
|
http_fetcher
|
http_fetcher_library
|
Buffer overflow in the http_fetch function of HTTP Fetcher 1.0.0 and 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request via a lon…
|
NVD-CWE-Other
|
CVE-2003-1262
|
2016-10-18 11:39 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345012
|
7.8 |
HIGH
|
-
|
-
|
Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.
|
NVD-CWE-Other
|
CVE-2003-1318
|
2016-10-18 11:39 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345013
|
5.0 |
MEDIUM
|
truegalerie
|
truegalerie
|
upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.
|
CWE-287
Improper Authentication
|
CVE-2003-1489
|
2016-10-18 11:39 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345014
|
7.5 |
HIGH
|
gnu
|
cfengine
|
Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction fu…
|
NVD-CWE-Other
|
CVE-2003-0849
|
2016-10-18 11:38 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345015
|
7.5 |
HIGH
|
dug_song rafal_wojtczuk
|
dsniff libnids
|
The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."
|
NVD-CWE-Other
|
CVE-2003-0850
|
2016-10-18 11:38 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345016
|
7.5 |
HIGH
|
mpg123
|
mpg123
|
Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.
|
NVD-CWE-Other
|
CVE-2003-0865
|
2016-10-18 11:38 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345017
|
2.1 |
LOW
|
openslp
|
openslp
|
Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.
|
NVD-CWE-Other
|
CVE-2003-0875
|
2016-10-18 11:38 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345018
|
10.0 |
HIGH
|
hylafax
|
hylafax
|
Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0886
|
2016-10-18 11:38 |
2003-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345019
|
7.5 |
HIGH
|
sun
|
jre
|
The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and exe…
|
NVD-CWE-Other
|
CVE-2003-0896
|
2016-10-18 11:38 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345020
|
4.6 |
MEDIUM
|
ibm
|
db2_universal_database
|
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.
|
NVD-CWE-Other
|
CVE-2003-0898
|
2016-10-18 11:38 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345021
|
7.5 |
HIGH
|
clearswift
|
mailsweeper
|
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter RAR 3.20 encoded files, which allows remote attackers to bypass intended policy.
|
NVD-CWE-Other
|
CVE-2003-0928
|
2016-10-18 11:38 |
2004-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345022
|
7.5 |
HIGH
|
clearswift
|
mailsweeper
|
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.
|
NVD-CWE-Other
|
CVE-2003-0929
|
2016-10-18 11:38 |
2004-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345023
|
7.5 |
HIGH
|
clearswift
|
mailsweeper
|
Clearswift MAILsweeper before 4.3.15 does not properly detect filenames in BinHex (HQX) encoded files, which allows remote attackers to bypass intended policy.
|
NVD-CWE-Other
|
CVE-2003-0930
|
2016-10-18 11:38 |
2004-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345024
|
4.6 |
MEDIUM
|
symbol_technologies
|
pdt
|
Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.
|
NVD-CWE-Other
|
CVE-2003-0934
|
2016-10-18 11:38 |
2003-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345025
|
7.2 |
HIGH
|
symantec
|
pcanywhere
|
Symantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using AWHOST32.exe.
|
NVD-CWE-Other
|
CVE-2003-0936
|
2016-10-18 11:38 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345026
|
7.5 |
HIGH
|
clam_anti-virus
|
clamav
|
Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary…
|
NVD-CWE-Other
|
CVE-2003-0946
|
2016-10-18 11:38 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345027
|
4.6 |
MEDIUM
|
openbsd
|
openbsd
|
OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled …
|
NVD-CWE-Other
|
CVE-2003-0955
|
2016-10-18 11:38 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345028
|
7.5 |
HIGH
|
openca
|
openca
|
OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.
|
NVD-CWE-Other
|
CVE-2003-0960
|
2016-10-18 11:38 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345029
|
7.2 |
HIGH
|
linux
|
linux_kernel
|
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2003-0961
|
2016-10-18 11:38 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345030
|
10.0 |
HIGH
|
-
|
-
|
Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribut…
|
NVD-CWE-Other
|
CVE-2003-0968
|
2016-10-18 11:38 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345031
|
10.0 |
HIGH
|
gnu
|
screen
|
Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape se…
|
NVD-CWE-Other
|
CVE-2003-0972
|
2016-10-18 11:38 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345032
|
7.5 |
HIGH
|
applied_watch_technologies
|
applied_watch_command_center
|
Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console, as demonstrated using appliedsnatch.c, or (2) a…
|
NVD-CWE-Other
|
CVE-2003-0974
|
2016-10-18 11:38 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345033
|
5.0 |
MEDIUM
|
freescripts
|
visitorbook
|
FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra h…
|
NVD-CWE-Other
|
CVE-2003-0979
|
2016-10-18 11:38 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345034
|
4.3 |
MEDIUM
|
freescripts
|
visitorbook
|
Cross-site scripting (XSS) vulnerability in FreeScripts VisitorBook LE (visitorbook.pl) allows remote attackers to inject arbitrary HTML or web script via (1) the "do" parameter, (2) via the "user" p…
|
NVD-CWE-Other
|
CVE-2003-0980
|
2016-10-18 11:38 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345035
|
7.2 |
HIGH
|
symantec
|
norton_antivirus norton_internet_security norton_system_works windows_liveupdate
|
The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and …
|
NVD-CWE-Other
|
CVE-2003-0994
|
2016-10-18 11:38 |
2004-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345036
|
6.8 |
MEDIUM
|
phpwebsite
|
phpwebsite
|
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fa…
|
NVD-CWE-Other
|
CVE-2003-0736
|
2016-10-18 11:37 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345037
|
5.0 |
MEDIUM
|
phpwebsite
|
phpwebsite
|
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of…
|
NVD-CWE-Other
|
CVE-2003-0737
|
2016-10-18 11:37 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345038
|
7.8 |
HIGH
|
phpwebsite
|
phpwebsite
|
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2003-0738
|
2016-10-18 11:37 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345039
|
4.6 |
MEDIUM
|
vmware
|
workstation
|
VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2003-0739
|
2016-10-18 11:37 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345040
|
4.6 |
MEDIUM
|
stunnel
|
stunnel
|
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.
|
NVD-CWE-Other
|
CVE-2003-0740
|
2016-10-18 11:37 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345041
|
7.5 |
HIGH
|
university_of_cambridge
|
exim
|
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument…
|
NVD-CWE-Other
|
CVE-2003-0743
|
2016-10-18 11:37 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345042
|
5.0 |
MEDIUM
|
leafnode
|
leafnode
|
The fetchnews NNTP client in leafnode 1.9.3 to 1.9.41 allows remote attackers to cause a denial of service (process hang and termination) via certain malformed Usenet news articles that cause fetchne…
|
NVD-CWE-Other
|
CVE-2003-0744
|
2016-10-18 11:37 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345043
|
7.2 |
HIGH
|
ibm
|
db2_universal_database
|
Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.
|
NVD-CWE-Other
|
CVE-2003-0759
|
2016-10-18 11:37 |
2003-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345044
|
4.3 |
MEDIUM
|
squished_mosquito
|
escapade
|
Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method parameter, as demonstrated using the PAGE parameter.
|
NVD-CWE-Other
|
CVE-2003-0763
|
2016-10-18 11:37 |
2003-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345045
|
5.0 |
MEDIUM
|
squished_mosquito
|
escapade
|
Escapade Scripting Engine (ESP) allows remote attackers to obtain sensitive path information via a malformed request, which leaks the information in an error message, as demonstrated using the PAGE p…
|
NVD-CWE-Other
|
CVE-2003-0764
|
2016-10-18 11:37 |
2003-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345046
|
7.5 |
HIGH
|
nullsoft
|
winamp
|
The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.
|
NVD-CWE-Other
|
CVE-2003-0765
|
2016-10-18 11:37 |
2003-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345047
|
7.5 |
HIGH
|
gamespy
|
roger_wilco_dedicated_server roger_wilco_graphical_server
|
Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers to cause a denial o…
|
NVD-CWE-Other
|
CVE-2003-0767
|
2016-10-18 11:37 |
2003-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345048
|
6.8 |
MEDIUM
|
microsoft
|
asp.net
|
Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.
|
NVD-CWE-Other
|
CVE-2003-0768
|
2016-10-18 11:37 |
2003-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345049
|
7.5 |
HIGH
|
ikonboard.com
|
ikonboard
|
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when…
|
NVD-CWE-Other
|
CVE-2003-0770
|
2016-10-18 11:37 |
2003-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345050
|
4.6 |
MEDIUM
|
apache_gallery
|
apache_gallery
|
Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apa…
|
NVD-CWE-Other
|
CVE-2003-0771
|
2016-10-18 11:37 |
2003-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|