|
347401
|
5.0 |
MEDIUM
|
debian
|
debian_linux
|
Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.
|
NVD-CWE-Other
|
CVE-2003-0362
|
2008-09-6 05:34 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347402
|
7.5 |
HIGH
|
licq
|
licq
|
Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.
|
NVD-CWE-Other
|
CVE-2003-0363
|
2008-09-6 05:34 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347403
|
5.0 |
MEDIUM
|
lysator
|
lyskom-server
|
lyskom-server 2.0.7 and earlier allows unauthenticated users to cause a denial of service (CPU consumption) via a large query.
|
NVD-CWE-Other
|
CVE-2003-0366
|
2008-09-6 05:34 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347404
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority a…
|
NVD-CWE-Other
|
CVE-2003-0378
|
2008-09-6 05:34 |
2003-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347405
|
7.5 |
HIGH
|
atftpd
|
atftpd
|
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long fi…
|
NVD-CWE-Other
|
CVE-2003-0380
|
2008-09-6 05:34 |
2003-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347406
|
2.1 |
LOW
|
norman_ramsey
|
noweb
|
Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script.
|
NVD-CWE-Other
|
CVE-2003-0381
|
2008-09-6 05:34 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347407
|
4.3 |
MEDIUM
|
rsa
|
ace_agent
|
Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause u…
|
NVD-CWE-Other
|
CVE-2003-0389
|
2008-09-6 05:34 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347408
|
5.0 |
MEDIUM
|
smc_networks
|
barricade_wireless_cable_dsl_broadband_router
|
SMC Networks Barricade Wireless Cable/DSL Broadband Router SMC7004VWBR allows remote attackers to cause a denial of service via certain packets to PPTP port 1723 on the internal interface.
|
NVD-CWE-Other
|
CVE-2003-0419
|
2008-09-6 05:34 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347409
|
10.0 |
HIGH
|
apple
|
darwin_streaming_server
|
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different v…
|
NVD-CWE-Other
|
CVE-2003-0421
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347410
|
10.0 |
HIGH
|
apple
|
darwin_streaming_server
|
The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator passwo…
|
NVD-CWE-Other
|
CVE-2003-0426
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347411
|
7.5 |
HIGH
|
gnocatan-develop
|
gnocatan
|
Multiple buffer overflows in gnocatan 0.6.1 and earlier allow attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0433
|
2008-09-6 05:34 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347412
|
1.2 |
LOW
|
yuuichi_teranishi
|
eldav
|
eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2003-0438
|
2008-09-6 05:34 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347413
|
7.5 |
HIGH
|
webfs
|
webfs
|
Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.
|
NVD-CWE-Other
|
CVE-2003-0445
|
2008-09-6 05:34 |
2003-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347414
|
4.6 |
MEDIUM
|
xblockout
|
xbl
|
Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.
|
NVD-CWE-Other
|
CVE-2003-0451
|
2008-09-6 05:34 |
2003-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347415
|
4.6 |
MEDIUM
|
gunnar_ritter
|
osh
|
Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."
|
NVD-CWE-Other
|
CVE-2003-0452
|
2008-09-6 05:34 |
2003-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347416
|
7.2 |
HIGH
|
joe_rumsey
|
xgalaga
|
Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2003-0454
|
2008-09-6 05:34 |
2003-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347417
|
4.6 |
MEDIUM
|
hp
|
nonstop_seeview_server_gateway
|
Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.
|
NVD-CWE-Other
|
CVE-2003-0458
|
2008-09-6 05:34 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347418
|
7.2 |
HIGH
|
michael_c._toren
|
tcptraceroute
|
tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulne…
|
NVD-CWE-Other
|
CVE-2003-0489
|
2008-09-6 05:34 |
2003-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347419
|
10.0 |
HIGH
|
proftpd_project
|
proftpd
|
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing au…
|
NVD-CWE-Other
|
CVE-2003-0500
|
2008-09-6 05:34 |
2003-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347420
|
7.5 |
HIGH
|
apple
|
safari
|
Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to s…
|
NVD-CWE-Other
|
CVE-2003-0514
|
2008-09-6 05:34 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347421
|
4.6 |
MEDIUM
|
daiki_ueno
|
liece_emacs_irc_client
|
The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.
|
NVD-CWE-Other
|
CVE-2003-0537
|
2008-09-6 05:34 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347422
|
5.0 |
MEDIUM
|
sgi
|
irix
|
The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.
|
NVD-CWE-Other
|
CVE-2003-0573
|
2008-09-6 05:34 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347423
|
10.0 |
HIGH
|
phpgroupware
|
phpgroupware
|
Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path being under the web do…
|
NVD-CWE-Other
|
CVE-2003-0599
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347424
|
6.8 |
MEDIUM
|
mozilla
|
bugzilla
|
Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default Ge…
|
NVD-CWE-Other
|
CVE-2003-0602
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347425
|
2.1 |
LOW
|
mozilla
|
bugzilla
|
Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with …
|
NVD-CWE-Other
|
CVE-2003-0603
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347426
|
4.6 |
MEDIUM
|
xtokkaetama
|
xtokkaetama
|
Multiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line argument or (2) XTOKKAETAMADIR environment variable.
|
NVD-CWE-Other
|
CVE-2003-0611
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347427
|
7.5 |
HIGH
|
novell
|
ichain
|
Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.
|
NVD-CWE-Other
|
CVE-2003-0636
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347428
|
10.0 |
HIGH
|
bea
|
weblogic_server
|
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privile…
|
NVD-CWE-Other
|
CVE-2003-0640
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347429
|
4.6 |
MEDIUM
|
johannes_sixt
|
kdbg
|
Kdbg 1.1.0 through 1.2.8 does not check permissions of the .kdbgrc file, which allows local users to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2003-0644
|
2008-09-6 05:34 |
2003-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347430
|
7.5 |
HIGH
|
mod_mylo
|
mod_mylo
|
Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2003-0651
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347431
|
7.5 |
HIGH
|
phpgroupware
|
phpgroupware
|
Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct unauthorized database actions.
|
NVD-CWE-Other
|
CVE-2003-0657
|
2008-09-6 05:34 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347432
|
7.5 |
HIGH
|
sgi
|
irix
|
NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypas…
|
NVD-CWE-Other
|
CVE-2003-0683
|
2008-09-6 05:34 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347433
|
7.2 |
HIGH
|
hp
|
hp-ux
|
Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.
|
NVD-CWE-Other
|
CVE-2003-0061
|
2008-09-6 05:33 |
2002-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347434
|
5.0 |
MEDIUM
|
nokia
|
6210_handset
|
Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of form…
|
NVD-CWE-Other
|
CVE-2003-0103
|
2008-09-6 05:33 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347435
|
5.0 |
MEDIUM
|
peoplesoft
|
peopletools
|
Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.
|
NVD-CWE-Other
|
CVE-2003-0104
|
2008-09-6 05:33 |
2003-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347436
|
7.5 |
HIGH
|
ibm
|
aix
|
The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorize…
|
NVD-CWE-Other
|
CVE-2003-0119
|
2008-09-6 05:33 |
2004-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347437
|
1.2 |
LOW
|
mhc-utils
|
mhc-utils
|
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.
|
NVD-CWE-Other
|
CVE-2003-0120
|
2008-09-6 05:33 |
2003-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347438
|
7.5 |
HIGH
|
multitech
|
routefinder_550_vpn
|
The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to …
|
NVD-CWE-Other
|
CVE-2003-0126
|
2008-09-6 05:33 |
2003-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347439
|
5.0 |
MEDIUM
|
adobe
|
acrobat_reader
|
Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, whic…
|
NVD-CWE-Other
|
CVE-2003-0142
|
2008-09-6 05:33 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347440
|
7.5 |
HIGH
|
mozilla
|
bonsai
|
Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.
|
NVD-CWE-Other
|
CVE-2003-0152
|
2008-09-6 05:33 |
2003-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347441
|
5.0 |
MEDIUM
|
mozilla
|
bonsai
|
bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.
|
NVD-CWE-Other
|
CVE-2003-0155
|
2008-09-6 05:33 |
2003-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347442
|
7.5 |
HIGH
|
mutt
|
mutt
|
Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and pos…
|
NVD-CWE-Other
|
CVE-2003-0167
|
2008-09-6 05:33 |
2003-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347443
|
5.0 |
MEDIUM
|
sgi
|
irix
|
The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP p…
|
NVD-CWE-Other
|
CVE-2003-0176
|
2008-09-6 05:33 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347444
|
4.6 |
MEDIUM
|
sgi
|
irix
|
SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.
|
NVD-CWE-Other
|
CVE-2003-0177
|
2008-09-6 05:33 |
2003-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347445
|
4.6 |
MEDIUM
|
redhat
|
tcpdump linux
|
tcpdump does not properly drop privileges to the pcap user when starting up.
|
NVD-CWE-Other
|
CVE-2003-0194
|
2008-09-6 05:33 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347446
|
4.6 |
MEDIUM
|
debian
|
mime-support
|
run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2003-0214
|
2008-09-6 05:33 |
2003-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347447
|
7.5 |
HIGH
|
frontrange
|
goldmine
|
FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attacker…
|
NVD-CWE-Other
|
CVE-2003-0241
|
2008-09-6 05:33 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347448
|
7.5 |
HIGH
|
adobe
|
acrobat
|
Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated…
|
NVD-CWE-Other
|
CVE-2003-0284
|
2008-09-6 05:33 |
2003-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347449
|
5.8 |
MEDIUM
|
neosoft
|
neobook
|
The NBActiveX.ocx ActiveX control in NeoBook 4 allows remote attackers to install and execute arbitrary programs.
|
NVD-CWE-Other
|
CVE-2002-2352
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347450
|
7.8 |
HIGH
|
netgear
|
fm114p
|
Netgear FM114P firmware 1.3 wireless firewall allows remote attackers to cause a denial of service (crash or hang) via a large number of TCP connection requests.
|
CWE-20
Improper Input Validation
|
CVE-2002-2354
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|