|
345051
|
5.0 |
MEDIUM
|
gnu quagga sgi
|
zebra quagga propack
|
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial…
|
CWE-20
Improper Input Validation
|
CVE-2003-0795
|
2016-10-18 11:37 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345052
|
7.5 |
HIGH
|
university_of_minnesota
|
gopherd
|
Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisTex…
|
NVD-CWE-Other
|
CVE-2003-0805
|
2016-10-18 11:37 |
2003-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345053
|
7.5 |
HIGH
|
gnu
|
lsh
|
lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attacke…
|
NVD-CWE-Other
|
CVE-2003-0826
|
2016-10-18 11:37 |
2003-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345054
|
5.0 |
MEDIUM
|
ibm
|
db2_universal_database
|
The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.
|
NVD-CWE-Other
|
CVE-2003-0827
|
2016-10-18 11:37 |
2003-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345055
|
7.5 |
HIGH
|
mplayer
|
mplayer
|
Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.
|
NVD-CWE-Other
|
CVE-2003-0835
|
2016-10-18 11:37 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345056
|
5.0 |
MEDIUM
|
microsoft
|
windows_2003_server
|
Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.
|
NVD-CWE-Other
|
CVE-2003-0839
|
2016-10-18 11:37 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345057
|
7.2 |
HIGH
|
hp
|
hp-ux
|
Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.
|
NVD-CWE-Other
|
CVE-2003-0840
|
2016-10-18 11:37 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345058
|
7.5 |
HIGH
|
dag_apt_repository
|
mod_gzip
|
Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code …
|
NVD-CWE-Other
|
CVE-2003-0842
|
2016-10-18 11:37 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345059
|
7.5 |
HIGH
|
dag_apt_repository
|
mod_gzip
|
Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers t…
|
NVD-CWE-Other
|
CVE-2003-0843
|
2016-10-18 11:37 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345060
|
4.6 |
MEDIUM
|
suse
|
suse_linux
|
SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on the .java_wrapper temporary file.
|
NVD-CWE-Other
|
CVE-2003-0846
|
2016-10-18 11:37 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345061
|
4.6 |
MEDIUM
|
suse
|
suse_linux
|
SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.
|
NVD-CWE-Other
|
CVE-2003-0847
|
2016-10-18 11:37 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345062
|
5.0 |
MEDIUM
|
peoplesoft
|
peopletools
|
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP…
|
NVD-CWE-Other
|
CVE-2003-0628
|
2016-10-18 11:36 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345063
|
4.3 |
MEDIUM
|
peoplesoft
|
peopletools
|
Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScrip…
|
NVD-CWE-Other
|
CVE-2003-0629
|
2016-10-18 11:36 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345064
|
7.2 |
HIGH
|
atari800
|
atari800
|
Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line arguments, as demonstrate…
|
NVD-CWE-Other
|
CVE-2003-0630
|
2016-10-18 11:36 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345065
|
7.2 |
HIGH
|
vmware
|
gsx_server workstation
|
VMware GSX Server 2.5.1 build 4968 and earlier, and Workstation 4.0 and earlier, allows local users to gain root privileges via certain enivronment variables that are used when launching a virtual ma…
|
NVD-CWE-Other
|
CVE-2003-0631
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345066
|
7.5 |
HIGH
|
oracle
|
applications e-business_suite
|
Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.5.8 may allow remote attackers to execute arbitrar…
|
NVD-CWE-Other
|
CVE-2003-0632
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345067
|
5.0 |
MEDIUM
|
oracle
|
applications e-business_suite
|
Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without…
|
NVD-CWE-Other
|
CVE-2003-0633
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345068
|
5.0 |
MEDIUM
|
novell
|
ichain
|
Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to (1) NCPIP.NLM and (2) JSTCP.NLM.
|
NVD-CWE-Other
|
CVE-2003-0635
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345069
|
7.5 |
HIGH
|
novell
|
ichain
|
Multiple buffer overflows in Novell iChain 2.1 before Field Patch 3, and iChain 2.2 before Field Patch 1a, allow attackers to cause a denial of service (ABEND) and possibly execute arbitrary code via…
|
NVD-CWE-Other
|
CVE-2003-0638
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345070
|
5.0 |
MEDIUM
|
novell
|
ichain
|
Unknown vulnerability in Novell iChain 2.2 before Support Pack 1 allows users to access restricted or secure pages without authentication.
|
NVD-CWE-Other
|
CVE-2003-0639
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345071
|
7.5 |
HIGH
|
gamespy
|
arcade
|
Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code via .. (dot dot) seq…
|
NVD-CWE-Other
|
CVE-2003-0650
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345072
|
4.6 |
MEDIUM
|
xtokkaetama
|
xtokkaetama
|
Buffer overflow in xtokkaetama allows local users to gain privileges via a long -nickname command line argument, a different vulnerability than CVE-2003-0611.
|
NVD-CWE-Other
|
CVE-2003-0652
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345073
|
7.2 |
HIGH
|
cdrtools
|
cdrtools
|
rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as a command line argument, which is modified while rscsi is …
|
NVD-CWE-Other
|
CVE-2003-0655
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345074
|
2.1 |
LOW
|
eroaster
|
eroaster
|
eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.
|
NVD-CWE-Other
|
CVE-2003-0656
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345075
|
5.0 |
MEDIUM
|
sun
|
iplanet_directory_server one_directory_server
|
Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.
|
NVD-CWE-Other
|
CVE-2003-0676
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345076
|
7.5 |
HIGH
|
netris
|
netris
|
Buffer overflow in Netris 0.52 and earlier, and possibly other versions, allows remote malicious Netris servers to execute arbitrary code on netris clients via a long server response.
|
NVD-CWE-Other
|
CVE-2003-0685
|
2016-10-18 11:36 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345077
|
6.4 |
MEDIUM
|
horde
|
horde
|
Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.
|
NVD-CWE-Other
|
CVE-2003-0728
|
2016-10-18 11:36 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345078
|
7.5 |
HIGH
|
tellurian
|
tftpdnt
|
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.
|
NVD-CWE-Other
|
CVE-2003-0729
|
2016-10-18 11:36 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345079
|
7.5 |
HIGH
|
xfree86_project netbsd
|
x11r6 netbsd
|
Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflo…
|
NVD-CWE-Other
|
CVE-2003-0730
|
2016-10-18 11:36 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345080
|
7.5 |
HIGH
|
phpwebsite
|
phpwebsite
|
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.
|
NVD-CWE-Other
|
CVE-2003-0735
|
2016-10-18 11:36 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345081
|
3.6 |
LOW
|
phpsysinfo
|
phpsysinfo
|
Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (do…
|
NVD-CWE-Other
|
CVE-2003-0536
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345082
|
7.5 |
HIGH
|
netscape
|
navigator
|
Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.
|
NVD-CWE-Other
|
CVE-2003-0553
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345083
|
5.0 |
MEDIUM
|
neomodus
|
direct_connect
|
NeoModus Direct Connect 1.0 build 9, and possibly other versions, allows remote attackers to cause a denial of service (connection and possibly memory exhaustion) via a flood of ConnectToMe requests …
|
NVD-CWE-Other
|
CVE-2003-0554
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345084
|
7.5 |
HIGH
|
imagemagick
|
imagemagick
|
ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability.
|
NVD-CWE-Other
|
CVE-2003-0555
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345085
|
5.0 |
MEDIUM
|
polycom
|
mgc-100 mgc-25 mgc-50
|
Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.
|
NVD-CWE-Other
|
CVE-2003-0556
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345086
|
7.5 |
HIGH
|
lagarde
|
storefront
|
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.
|
NVD-CWE-Other
|
CVE-2003-0557
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345087
|
7.5 |
HIGH
|
lagarde
|
storefront
|
This issue was addressed in a hot fix for StoreFront 6.1 in late January 2004.
|
NVD-CWE-Other
|
CVE-2003-0557
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345088
|
7.5 |
HIGH
|
leapware
|
leapftp
|
Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.
|
NVD-CWE-Other
|
CVE-2003-0558
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345089
|
7.5 |
HIGH
|
phpforum
|
phpforum
|
mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server th…
|
NVD-CWE-Other
|
CVE-2003-0559
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345090
|
10.0 |
HIGH
|
virtual_programming
|
vp-asp
|
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.
|
NVD-CWE-Other
|
CVE-2003-0560
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345091
|
7.5 |
HIGH
|
iglooftp
|
iglooftp_pro
|
Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and …
|
NVD-CWE-Other
|
CVE-2003-0561
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345092
|
5.0 |
MEDIUM
|
novell
|
netware
|
Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.
|
NVD-CWE-Other
|
CVE-2003-0562
|
2016-10-18 11:35 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345093
|
4.6 |
MEDIUM
|
ibm
|
u2_universe
|
uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by pro…
|
NVD-CWE-Other
|
CVE-2003-0579
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345094
|
7.2 |
HIGH
|
ibm
|
u2_universe
|
Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.
|
NVD-CWE-Other
|
CVE-2003-0580
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345095
|
7.5 |
HIGH
|
xfstt
|
xfstt
|
X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and p…
|
NVD-CWE-Other
|
CVE-2003-0581
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345096
|
7.2 |
HIGH
|
tolis_group
|
bru
|
Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument.
|
NVD-CWE-Other
|
CVE-2003-0583
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345097
|
7.2 |
HIGH
|
tolis_group
|
bru
|
Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command …
|
NVD-CWE-Other
|
CVE-2003-0584
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345098
|
7.5 |
HIGH
|
brooky
|
estore
|
SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.
|
NVD-CWE-Other
|
CVE-2003-0585
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345099
|
7.5 |
HIGH
|
brooky
|
estore
|
Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.
|
NVD-CWE-Other
|
CVE-2003-0586
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345100
|
6.9 |
MEDIUM
|
infopop
|
ultimate_bulletin_board
|
Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "display…
|
NVD-CWE-Other
|
CVE-2003-0587
|
2016-10-18 11:35 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|