|
347351
|
5.1 |
MEDIUM
|
sonicwall
|
firmware
|
SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including…
|
CWE-399
Resource Management Errors
|
CVE-2003-1320
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347352
|
10.0 |
HIGH
|
atrium_software
|
mercur_mailserver
|
Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (…
|
NVD-CWE-Other
|
CVE-2003-1322
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347353
|
6.8 |
MEDIUM
|
elm_development_group
|
elm
|
Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group …
|
NVD-CWE-Other
|
CVE-2003-1323
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347354
|
4.6 |
MEDIUM
|
elmme-mailer
|
elm_me\+
|
Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the …
|
NVD-CWE-Other
|
CVE-2003-1324
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347355
|
5.2 |
MEDIUM
|
valve_software
|
half-life_cstrike_dedicated_server
|
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemo…
|
NVD-CWE-Other
|
CVE-2003-1325
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347356
|
7.8 |
HIGH
|
washington_university
|
wu-ftpd
|
ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers…
|
NVD-CWE-Other
|
CVE-2003-1329
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347357
|
6.4 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mo…
|
NVD-CWE-Other
|
CVE-2003-1363
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347358
|
3.6 |
LOW
|
ralf_hoffmann
|
worker_filemanager
|
Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2003-1460
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347359
|
7.5 |
HIGH
|
tomi_manninen
|
linuxnode
|
Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0707
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347360
|
7.5 |
HIGH
|
tomi_manninen
|
linuxnode
|
Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0708
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347361
|
7.5 |
HIGH
|
compaq
|
tru64
|
ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2003-0724
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347362
|
7.5 |
HIGH
|
realnetworks
|
helix_universal_server realserver
|
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows…
|
NVD-CWE-Other
|
CVE-2003-0725
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347363
|
10.0 |
HIGH
|
cisco
|
resource_manager resource_manager_essentials ciscoworks_common_management_foundation ciscoworks_cd1
|
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Ad…
|
NVD-CWE-Other
|
CVE-2003-0732
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347364
|
6.8 |
MEDIUM
|
bea
|
liquid_data weblogic_integration weblogic_server
|
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary …
|
NVD-CWE-Other
|
CVE-2003-0733
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347365
|
5.0 |
MEDIUM
|
hp
|
openview
|
Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs,…
|
NVD-CWE-Other
|
CVE-2003-0746
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347366
|
6.8 |
MEDIUM
|
sap
|
internet_transaction_server
|
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~servi…
|
NVD-CWE-Other
|
CVE-2003-0749
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347367
|
7.5 |
HIGH
|
attila-php.net
|
attilaphp
|
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.
|
NVD-CWE-Other
|
CVE-2003-0752
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347368
|
5.0 |
MEDIUM
|
checkpoint
|
firewall-1
|
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP add…
|
NVD-CWE-Other
|
CVE-2003-0757
|
2008-09-6 05:35 |
2003-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347369
|
7.5 |
HIGH
|
digium
|
asterisk
|
Buffer overflow in the get_msg_text of chan_sip.c in the Session Initiation Protocol (SIP) protocol implementation for Asterisk releases before August 15, 2003, allows remote attackers to execute arb…
|
NVD-CWE-Other
|
CVE-2003-0761
|
2008-09-6 05:35 |
2003-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347370
|
7.8 |
HIGH
|
charles_kerr
|
pan
|
Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.
|
NVD-CWE-Other
|
CVE-2003-0855
|
2008-09-6 05:35 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347371
|
4.6 |
MEDIUM
|
redhat
|
enterprise_linux
|
The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2003-0857
|
2008-09-6 05:35 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347372
|
2.1 |
LOW
|
sco
|
openserver
|
Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2003-0872
|
2008-09-6 05:35 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347373
|
2.1 |
LOW
|
apple
|
mac_os_x
|
slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.
|
NVD-CWE-Other
|
CVE-2003-0878
|
2008-09-6 05:35 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347374
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.
|
NVD-CWE-Other
|
CVE-2003-0880
|
2008-09-6 05:35 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347375
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by…
|
NVD-CWE-Other
|
CVE-2003-0881
|
2008-09-6 05:35 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347376
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.
|
NVD-CWE-Other
|
CVE-2003-0882
|
2008-09-6 05:35 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347377
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.
|
NVD-CWE-Other
|
CVE-2003-0883
|
2008-09-6 05:35 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347378
|
6.4 |
MEDIUM
|
xscreensaver
|
xscreensaver
|
Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensa…
|
NVD-CWE-Other
|
CVE-2003-0885
|
2008-09-6 05:35 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347379
|
2.1 |
LOW
|
angus_mackay
|
ez-ipupdate
|
ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file.
|
NVD-CWE-Other
|
CVE-2003-0887
|
2008-09-6 05:35 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347380
|
5.0 |
MEDIUM
|
larry_wall
|
perl
|
Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.
|
NVD-CWE-Other
|
CVE-2003-0900
|
2008-09-6 05:35 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347381
|
7.5 |
HIGH
|
postgresql
|
postgresql
|
Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0901
|
2008-09-6 05:35 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347382
|
7.5 |
HIGH
|
sap
|
sap_db
|
eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code via a connect packet with a 256 byte segment to the …
|
NVD-CWE-Other
|
CVE-2003-0939
|
2008-09-6 05:35 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347383
|
5.0 |
MEDIUM
|
sap
|
sap_db
|
Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.
|
NVD-CWE-Other
|
CVE-2003-0940
|
2008-09-6 05:35 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347384
|
7.5 |
HIGH
|
sap
|
sap_db
|
web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.
|
NVD-CWE-Other
|
CVE-2003-0941
|
2008-09-6 05:35 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347385
|
7.5 |
HIGH
|
sap
|
sap_db
|
Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a long Name parameter to waadmin.wa.
|
NVD-CWE-Other
|
CVE-2003-0942
|
2008-09-6 05:35 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347386
|
7.5 |
HIGH
|
sap
|
sap_db
|
web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially sensitive information or redirect attacks against …
|
NVD-CWE-Other
|
CVE-2003-0943
|
2008-09-6 05:35 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347387
|
7.5 |
HIGH
|
sap
|
sap_db
|
Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL with a long requestURI.
|
NVD-CWE-Other
|
CVE-2003-0944
|
2008-09-6 05:35 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347388
|
7.2 |
HIGH
|
wireless_tools
|
wireless_tools
|
Buffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2003-0948
|
2008-09-6 05:35 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347389
|
7.2 |
HIGH
|
ibm
|
aix
|
Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2003-0954
|
2008-09-6 05:35 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347390
|
5.0 |
MEDIUM
|
sun
|
sun_fire
|
The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporarily disabled.
|
NVD-CWE-Other
|
CVE-2003-0970
|
2008-09-6 05:35 |
2003-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347391
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (…
|
NVD-CWE-Other
|
CVE-2003-1031
|
2008-09-6 05:35 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347392
|
5.0 |
MEDIUM
|
mod_access_referer
|
mod_access_referer
|
mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in A…
|
NVD-CWE-Other
|
CVE-2003-1054
|
2008-09-6 05:35 |
2003-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347393
|
5.0 |
MEDIUM
|
fourelle_venturi_wireless
|
venturi_client
|
Venturi Client before 2.2, as used in certain Fourelle and Venturi Wireless products, can be used as an open proxy for various protocols, including an open relay for SMTP, which allows it to be abuse…
|
NVD-CWE-Other
|
CVE-2003-0316
|
2008-09-6 05:34 |
2003-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347394
|
5.0 |
MEDIUM
|
colten_edwards
|
bitchx
|
Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).
|
NVD-CWE-Other
|
CVE-2003-0322
|
2008-09-6 05:34 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347395
|
7.5 |
HIGH
|
epic
|
epic4
|
EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP reques…
|
NVD-CWE-Other
|
CVE-2003-0328
|
2008-09-6 05:34 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347396
|
7.5 |
HIGH
|
demarc_security
|
puresecure
|
Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges.
|
NVD-CWE-Other
|
CVE-2003-0340
|
2008-09-6 05:34 |
2003-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347397
|
5.0 |
MEDIUM
|
apple kde
|
safari konqueror_embedded
|
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
|
NVD-CWE-Other
|
CVE-2003-0355
|
2008-09-6 05:34 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347398
|
4.6 |
MEDIUM
|
stichting_mathematisch_centrum
|
nethack
|
nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.
|
NVD-CWE-Other
|
CVE-2003-0359
|
2008-09-6 05:34 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347399
|
7.5 |
HIGH
|
debian
|
debian_linux
|
Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0360
|
2008-09-6 05:34 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347400
|
7.5 |
HIGH
|
debian
|
debian_linux
|
gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.
|
NVD-CWE-Other
|
CVE-2003-0361
|
2008-09-6 05:34 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|