|
346051
|
4.3 |
MEDIUM
|
dmxready
|
dmxready_site_chassis_manager
|
Cross-site scripting (XSS) vulnerability in DMXReady Site Chassis Manager allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2188
|
2008-09-11 04:33 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346052
|
7.5 |
HIGH
|
david_maciejak
|
athena_web_registration
|
athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.
|
NVD-CWE-Other
|
CVE-2004-1782
|
2008-09-11 04:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346053
|
5.0 |
MEDIUM
|
openldap
|
openldap
|
Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).
|
NVD-CWE-Other
|
CVE-2004-1880
|
2008-09-11 04:32 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346054
|
7.5 |
HIGH
|
apple
|
safari
|
Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "…
|
NVD-CWE-Other
|
CVE-2004-1122
|
2008-09-11 04:29 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346055
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other…
|
NVD-CWE-Other
|
CVE-2004-0925
|
2008-09-11 04:28 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346056
|
7.2 |
HIGH
|
gnu
|
mailutils
|
Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-0984
|
2008-09-11 04:28 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346057
|
5.0 |
MEDIUM
|
apple
|
quicktime
|
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memo…
|
NVD-CWE-Other
|
CVE-2004-0988
|
2008-09-11 04:28 |
2005-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346058
|
7.5 |
HIGH
|
mpg123 suse
|
mpg123 suse_linux
|
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
|
NVD-CWE-Other
|
CVE-2004-0991
|
2008-09-11 04:28 |
2005-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346059
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.
|
NVD-CWE-Other
|
CVE-2004-0086
|
2008-09-11 04:25 |
2004-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346060
|
2.1 |
LOW
|
apple
|
mac_os_x
|
The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.
|
NVD-CWE-Other
|
CVE-2004-0088
|
2008-09-11 04:25 |
2004-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346061
|
10.0 |
HIGH
|
apple
|
mac_os_x
|
Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.
|
NVD-CWE-Other
|
CVE-2004-0092
|
2008-09-11 04:25 |
2004-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346062
|
10.0 |
HIGH
|
freebsd
|
freebsd
|
The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets …
|
NVD-CWE-Other
|
CVE-2004-0002
|
2008-09-11 04:24 |
2004-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346063
|
5.0 |
MEDIUM
|
beasts
|
vsftpd
|
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
|
NVD-CWE-Other
|
CVE-2004-0042
|
2008-09-11 04:24 |
2004-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346064
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.
|
NVD-CWE-Other
|
CVE-2003-1220
|
2008-09-11 04:22 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346065
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communi…
|
NVD-CWE-Other
|
CVE-2003-1221
|
2008-09-11 04:22 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346066
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext …
|
NVD-CWE-Other
|
CVE-2003-1222
|
2008-09-11 04:22 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346067
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as d…
|
NVD-CWE-Other
|
CVE-2003-1223
|
2008-09-11 04:22 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346068
|
2.1 |
LOW
|
bea
|
weblogic_server
|
Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by…
|
NVD-CWE-Other
|
CVE-2003-1224
|
2008-09-11 04:22 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346069
|
2.1 |
LOW
|
bea
|
weblogic_server
|
The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.
|
NVD-CWE-Other
|
CVE-2003-1225
|
2008-09-11 04:22 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346070
|
2.1 |
LOW
|
bea
|
weblogic_server
|
BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to…
|
NVD-CWE-Other
|
CVE-2003-1226
|
2008-09-11 04:22 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346071
|
7.5 |
HIGH
|
cisco
|
80-7111-01_for_the_unity-svrx255-1a 80-7112-01_for_the_unity-svrx255-2a
|
Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bu…
|
NVD-CWE-Other
|
CVE-2003-0983
|
2008-09-11 04:21 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346072
|
5.0 |
MEDIUM
|
cisco
|
catalyst_6500 catalyst_6500_ws-svc-nam-1 catalyst_6500_ws-svc-nam-2 catalyst_6500_ws-x6380-nam catalyst_7600_ws-svc-nam-1 catalyst_7600_ws-svc-nam-2 catalyst_7600_ws-x6380-nam fi…
|
Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth reque…
|
NVD-CWE-Other
|
CVE-2003-1001
|
2008-09-11 04:21 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346073
|
5.0 |
MEDIUM
|
cisco
|
catalyst_6500 catalyst_6500_ws-svc-nam-1 catalyst_6500_ws-svc-nam-2 catalyst_6500_ws-x6380-nam catalyst_7600_ws-svc-nam-1 catalyst_7600_ws-svc-nam-2 catalyst_7600_ws-x6380-nam fi…
|
Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is …
|
NVD-CWE-Other
|
CVE-2003-1002
|
2008-09-11 04:21 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346074
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.
|
NVD-CWE-Other
|
CVE-2003-1005
|
2008-09-11 04:21 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346075
|
2.1 |
LOW
|
linux
|
linux_kernel
|
Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).
|
NVD-CWE-Other
|
CVE-2003-0643
|
2008-09-11 04:20 |
2003-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346076
|
7.5 |
HIGH
|
trend_micro
|
damage_cleanup_server housecall
|
Multiple buffer overflows in ActiveX controls used by Trend Micro HouseCall 5.5 and 5.7, and Damage Cleanup Server 1.0, allow remote attackers to execute arbitrary code via long parameter strings.
|
NVD-CWE-Other
|
CVE-2003-0646
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346077
|
7.5 |
HIGH
|
cisco
|
ios
|
Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.
|
NVD-CWE-Other
|
CVE-2003-0647
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346078
|
7.2 |
HIGH
|
xpcd
|
xpcd
|
Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2003-0649
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346079
|
5.0 |
MEDIUM
|
netbsd
|
netbsd
|
The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote a…
|
NVD-CWE-Other
|
CVE-2003-0653
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346080
|
7.5 |
HIGH
|
autorespond
|
autorespond
|
Buffer overflow in autorespond may allow remote attackers to execute arbitrary code as the autorespond user via qmail.
|
NVD-CWE-Other
|
CVE-2003-0654
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346081
|
2.1 |
LOW
|
sustainable_softworks
|
ipnetmonitorx ipnetsentryx
|
Sustworks IPNetSentryX and IPNetMonitorX allow local users to sniff network packets via the setuid helper applications (1) RunTCPDump, which calls tcpdump, and (2) RunTCPFlow, which calls tcpflow.
|
NVD-CWE-Other
|
CVE-2003-0670
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346082
|
7.2 |
HIGH
|
jeremy_elson
|
tcpflow
|
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMo…
|
NVD-CWE-Other
|
CVE-2003-0671
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346083
|
7.5 |
HIGH
|
leon_j_breedt
|
pam-pgsql
|
Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled whe…
|
NVD-CWE-Other
|
CVE-2003-0672
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346084
|
5.0 |
MEDIUM
|
cisco
|
webns
|
Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM…
|
NVD-CWE-Other
|
CVE-2003-0677
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346085
|
2.1 |
LOW
|
sgi
|
irix
|
Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allows local users to truncate or overwrite certain files.
|
NVD-CWE-Other
|
CVE-2003-0679
|
2008-09-11 04:20 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346086
|
7.5 |
HIGH
|
sgi
|
irix
|
Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.
|
NVD-CWE-Other
|
CVE-2003-0680
|
2008-09-11 04:20 |
2003-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346087
|
7.5 |
HIGH
|
redhat
|
enterprise_linux
|
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number…
|
NVD-CWE-Other
|
CVE-2003-0689
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346088
|
7.2 |
HIGH
|
ibm
|
aix
|
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
|
NVD-CWE-Other
|
CVE-2003-0697
|
2008-09-11 04:20 |
2003-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346089
|
7.5 |
HIGH
|
nicolas_boullis
|
mah-jong
|
Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0705
|
2008-09-11 04:20 |
2003-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346090
|
5.0 |
MEDIUM
|
nicolas_boullis
|
mah-jong
|
Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).
|
NVD-CWE-Other
|
CVE-2003-0706
|
2008-09-11 04:20 |
2003-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346091
|
7.5 |
HIGH
|
whois
|
whois
|
Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.
|
NVD-CWE-Other
|
CVE-2003-0709
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346092
|
7.5 |
HIGH
|
gkrellm
|
gkrellm
|
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0723
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346093
|
10.0 |
HIGH
|
cisco
|
resource_manager resource_manager_essentials ciscoworks_common_management_foundation ciscoworks_cd1
|
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly in…
|
NVD-CWE-Other
|
CVE-2003-0731
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346094
|
10.0 |
HIGH
|
padl_software
|
pam_ldap
|
Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the …
|
NVD-CWE-Other
|
CVE-2003-0734
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346095
|
10.0 |
HIGH
|
castle_rock_computing
|
snmpc
|
SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.
|
NVD-CWE-Other
|
CVE-2003-0745
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346096
|
7.5 |
HIGH
|
py-membres
|
py-membres
|
secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.
|
NVD-CWE-Other
|
CVE-2003-0750
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346097
|
7.5 |
HIGH
|
py-membres
|
py-membres
|
SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.
|
NVD-CWE-Other
|
CVE-2003-0751
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346098
|
5.0 |
MEDIUM
|
newsphp
|
newsphp
|
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.
|
NVD-CWE-Other
|
CVE-2003-0753
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346099
|
7.5 |
HIGH
|
newsphp
|
newsphp
|
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
|
NVD-CWE-Other
|
CVE-2003-0754
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346100
|
10.0 |
HIGH
|
gtkftpd
|
gtkftp
|
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.
|
NVD-CWE-Other
|
CVE-2003-0755
|
2008-09-11 04:20 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|