|
345151
|
2.1 |
LOW
|
hanterm
|
hanterm-xf
|
The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the termina…
|
NVD-CWE-Other
|
CVE-2003-0079
|
2016-10-18 11:29 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345152
|
10.0 |
HIGH
|
oracle
|
database_server oracle8i oracle9i
|
Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2003-0095
|
2016-10-18 11:29 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345153
|
9.0 |
HIGH
|
oracle
|
database_server oracle8i oracle9i
|
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTA…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2003-0096
|
2016-10-18 11:29 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345154
|
7.5 |
HIGH
|
cisco
|
ios
|
Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.
|
NVD-CWE-Other
|
CVE-2003-0100
|
2016-10-18 11:29 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345155
|
10.0 |
HIGH
|
engardelinux usermin webmin
|
guardian_digital_webtool usermin webmin
|
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic auth…
|
NVD-CWE-Other
|
CVE-2003-0101
|
2016-10-18 11:29 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345156
|
7.5 |
HIGH
|
symantec
|
enterprise_firewall
|
The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.
|
NVD-CWE-Other
|
CVE-2003-0106
|
2016-10-18 11:29 |
2003-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345157
|
5.0 |
MEDIUM
|
lbl
|
tcpdump
|
isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to ent…
|
NVD-CWE-Other
|
CVE-2003-0108
|
2016-10-18 11:29 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345158
|
7.5 |
HIGH
|
clearswift
|
mailsweeper
|
Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.
|
NVD-CWE-Other
|
CVE-2003-0121
|
2016-10-18 11:29 |
2003-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345159
|
2.1 |
LOW
|
mozilla
|
bugzilla
|
The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows l…
|
NVD-CWE-Other
|
CVE-2003-0012
|
2016-10-18 11:28 |
2003-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345160
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from e…
|
NVD-CWE-Other
|
CVE-2003-0013
|
2016-10-18 11:28 |
2003-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345161
|
5.0 |
MEDIUM
|
michael_jennings
|
eterm
|
The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user v…
|
NVD-CWE-Other
|
CVE-2003-0021
|
2016-10-18 11:28 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345162
|
5.0 |
MEDIUM
|
rxvt
|
rxvt
|
The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file c…
|
NVD-CWE-Other
|
CVE-2003-0022
|
2016-10-18 11:28 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345163
|
5.0 |
MEDIUM
|
rxvt
|
rxvt
|
The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.
|
NVD-CWE-Other
|
CVE-2003-0023
|
2016-10-18 11:28 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345164
|
7.5 |
HIGH
|
aterm
|
aterm
|
The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.
|
NVD-CWE-Other
|
CVE-2003-0024
|
2016-10-18 11:28 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345165
|
7.5 |
HIGH
|
horde
|
imp
|
Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as …
|
NVD-CWE-Other
|
CVE-2003-0025
|
2016-10-18 11:28 |
2003-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345166
|
10.0 |
HIGH
|
protegrity
|
secure.data
|
Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp…
|
NVD-CWE-Other
|
CVE-2003-0030
|
2016-10-18 11:28 |
2003-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345167
|
7.5 |
HIGH
|
mcrypt
|
libmcrypt
|
Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).
|
NVD-CWE-Other
|
CVE-2003-0031
|
2016-10-18 11:28 |
2003-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345168
|
5.0 |
MEDIUM
|
mcrypt
|
libmcrypt
|
Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load a…
|
NVD-CWE-Other
|
CVE-2003-0032
|
2016-10-18 11:28 |
2003-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345169
|
10.0 |
HIGH
|
snort
|
snort
|
Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.
|
NVD-CWE-Other
|
CVE-2003-0033
|
2016-10-18 11:28 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345170
|
4.6 |
MEDIUM
|
celestial_software
|
absolutetelnet
|
AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
|
NVD-CWE-Other
|
CVE-2003-0046
|
2016-10-18 11:28 |
2003-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345171
|
4.6 |
MEDIUM
|
van_dyke_technologies
|
entunnel securecrt securefx
|
SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, wh…
|
NVD-CWE-Other
|
CVE-2003-0047
|
2016-10-18 11:28 |
2003-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345172
|
4.6 |
MEDIUM
|
putty
|
putty
|
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
|
NVD-CWE-Other
|
CVE-2003-0048
|
2016-10-18 11:28 |
2003-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345173
|
7.5 |
HIGH
|
apple
|
darwin_streaming_server quicktime_streaming_server
|
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.
|
NVD-CWE-Other
|
CVE-2003-0050
|
2016-10-18 11:28 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345174
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server quicktime_streaming_server
|
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NU…
|
NVD-CWE-Other
|
CVE-2003-0051
|
2016-10-18 11:28 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345175
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server quicktime_streaming_server
|
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.
|
NVD-CWE-Other
|
CVE-2003-0052
|
2016-10-18 11:28 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345176
|
4.3 |
MEDIUM
|
apple
|
darwin_streaming_server quicktime_streaming_server
|
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script…
|
NVD-CWE-Other
|
CVE-2003-0053
|
2016-10-18 11:28 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345177
|
7.5 |
HIGH
|
apple
|
darwin_streaming_server quicktime_streaming_server
|
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to th…
|
NVD-CWE-Other
|
CVE-2003-0054
|
2016-10-18 11:28 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345178
|
7.5 |
HIGH
|
apple
|
quicktime_darwin_mp3_broadcaster
|
Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long …
|
NVD-CWE-Other
|
CVE-2003-0055
|
2016-10-18 11:28 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345179
|
7.2 |
HIGH
|
eset_software
|
nod32_antivirus
|
Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.
|
NVD-CWE-Other
|
CVE-2003-0062
|
2016-10-18 11:28 |
2003-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345180
|
4.3 |
MEDIUM
|
phorum
|
phorum
|
Cross-site scripting (XSS) vulnerability in read.php in Phorum 3.3.2a allows remote attackers to inject arbitrary web script or HTML via (1) the t parameter or (2) the body of an email response.
|
CWE-79
Cross-site Scripting
|
CVE-2002-2340
|
2016-10-18 11:28 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345181
|
5.0 |
MEDIUM
|
joe_depasquale
|
bannermatic
|
Bannermatic 1, 2, and 3 stores the (1) ban.log, (2) ban.bak, (3) ban.dat and (4) banmat.pwd data files under the web document root with insufficient access control, which allows attackers to obtain s…
|
CWE-200
Information Exposure
|
CVE-2002-2342
|
2016-10-18 11:28 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345182
|
10.0 |
HIGH
|
hughes_technologies
|
libhttpd
|
Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP POST request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2400
|
2016-10-18 11:28 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345183
|
10.0 |
HIGH
|
surecom
|
ep-4501
|
SURECOM broadband router EP-4501 uses a default SNMP read community string of "public" and a default SNMP read/write community string of "secret," which allows remote attackers to read and modify rou…
|
NVD-CWE-Other
|
CVE-2002-2402
|
2016-10-18 11:28 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345184
|
5.0 |
MEDIUM
|
curtis_specialty_consulting
|
iispop
|
Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2404
|
2016-10-18 11:28 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345185
|
4.3 |
MEDIUM
|
opera_software squid
|
opera squid
|
Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS conne…
|
NVD-CWE-Other
|
CVE-2002-2414
|
2016-10-18 11:28 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345186
|
7.2 |
HIGH
|
openbsd
|
openbsd
|
Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check…
|
NVD-CWE-Other
|
CVE-2002-1420
|
2016-10-18 11:27 |
2003-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345187
|
7.5 |
HIGH
|
mywebserver
|
mywebserver
|
Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.
|
NVD-CWE-Other
|
CVE-2002-1452
|
2016-10-18 11:27 |
2002-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345188
|
4.3 |
MEDIUM
|
mywebserver
|
mywebserver
|
Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user i…
|
NVD-CWE-Other
|
CVE-2002-1453
|
2016-10-18 11:27 |
2002-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345189
|
5.0 |
MEDIUM
|
mywebserver
|
mywebserver
|
MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.
|
NVD-CWE-Other
|
CVE-2002-1454
|
2016-10-18 11:27 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345190
|
1.2 |
LOW
|
stunnel
|
stunnel
|
stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions that cause an inconsistency in the child counter.
|
NVD-CWE-Other
|
CVE-2002-1563
|
2016-10-18 11:27 |
2003-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345191
|
5.0 |
MEDIUM
|
openssl
|
openssl
|
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that c…
|
NVD-CWE-Other
|
CVE-2002-1568
|
2016-10-18 11:27 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345192
|
5.0 |
MEDIUM
|
slashcode.com
|
slash
|
The quick login feature in Slash Slashcode does not redirect the user to an alternate URL when the wrong password is provided, which makes it easier for remote web sites to guess the proper passwords…
|
NVD-CWE-Other
|
CVE-2002-1647
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345193
|
6.4 |
MEDIUM
|
yahoo
|
messenger
|
Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2002-1664
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345194
|
7.5 |
HIGH
|
yahoo
|
messenger
|
Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long set_buddygrp field.
|
NVD-CWE-Other
|
CVE-2002-1665
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345195
|
5.0 |
MEDIUM
|
ibm
|
http_server
|
IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non…
|
NVD-CWE-Other
|
CVE-2002-1822
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345196
|
5.0 |
MEDIUM
|
openbb
|
openbb
|
Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters.
|
NVD-CWE-Other
|
CVE-2002-1830
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345197
|
7.5 |
HIGH
|
bizdesign
|
imagefolio
|
The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph…
|
NVD-CWE-Other
|
CVE-2002-1867
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345198
|
2.1 |
LOW
|
qnx
|
rtos
|
/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.
|
NVD-CWE-Other
|
CVE-2002-2039
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345199
|
7.5 |
HIGH
|
michael_baumer
|
pfinger
|
Buffer overflow in PFinger 0.7.8 client allows remote attackers to execute arbitrary code via a long query value passed to the (1) finger program, (2) -l, (3) -d, and (4) -t options. NOTE: if PFinge…
|
NVD-CWE-Other
|
CVE-2002-2048
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345200
|
7.5 |
HIGH
|
teekai
|
teekai_forum
|
TeeKai Forum 1.2 allows remote attackers to authenticate as the administrator and and gain privileged web forum access by setting the valid_level cookie to admin.
|
NVD-CWE-Other
|
CVE-2002-2054
|
2016-10-18 11:27 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|