|
312351
|
4.6 |
MEDIUM
|
uim mandrakesoft
|
uim mandrake_linux
|
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0503
|
2008-09-11 04:36 |
2005-02-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312352
|
4.6 |
MEDIUM
|
-
|
-
|
Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."
|
NVD-CWE-Other
|
CVE-2005-0508
|
2008-09-11 04:36 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312353
|
7.5 |
HIGH
|
mcafee
|
antivirus_engine
|
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.
|
NVD-CWE-Other
|
CVE-2005-0643
|
2008-09-11 04:36 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312354
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.
|
NVD-CWE-Other
|
CVE-2005-0712
|
2008-09-11 04:36 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312355
|
5.0 |
MEDIUM
|
clam_anti-virus
|
clamav
|
ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.
|
NVD-CWE-Other
|
CVE-2005-0133
|
2008-09-11 04:35 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312356
|
7.5 |
HIGH
|
smartlist
|
smartlist
|
The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie…
|
NVD-CWE-Other
|
CVE-2005-0157
|
2008-09-11 04:35 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312357
|
5.0 |
MEDIUM
|
clam_anti-virus
|
clamav
|
ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.
|
NVD-CWE-Other
|
CVE-2005-0218
|
2008-09-11 04:35 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312358
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (…
|
NVD-CWE-Other
|
CVE-2005-0258
|
2008-09-11 04:35 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312359
|
6.4 |
MEDIUM
|
phpbb_group
|
phpbb
|
phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, th…
|
NVD-CWE-Other
|
CVE-2005-0259
|
2008-09-11 04:35 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312360
|
4.3 |
MEDIUM
|
zakon_group
|
openconf
|
Cross-site scripting (XSS) vulnerability in Openconf 1.04, and possibly other versions before 1.10, allows remote attackers to inject arbitrary HTML and web script via the paper title.
|
NVD-CWE-Other
|
CVE-2005-0407
|
2008-09-11 04:35 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312361
|
6.4 |
MEDIUM
|
citrusdb
|
citrusdb
|
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such …
|
NVD-CWE-Other
|
CVE-2005-0409
|
2008-09-11 04:35 |
2005-02-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312362
|
5.0 |
MEDIUM
|
citrusdb
|
citrusdb
|
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.
|
NVD-CWE-Other
|
CVE-2005-0410
|
2008-09-11 04:35 |
2005-02-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312363
|
7.5 |
HIGH
|
citrusdb
|
citrusdb
|
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.
|
NVD-CWE-Other
|
CVE-2005-0411
|
2008-09-11 04:35 |
2005-02-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312364
|
10.0 |
HIGH
|
gentoo
|
poppassd_pam
|
poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.
|
NVD-CWE-Other
|
CVE-2005-0002
|
2008-09-11 04:34 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312365
|
4.3 |
MEDIUM
|
dmxready
|
dmxready_site_chassis_manager
|
Cross-site scripting (XSS) vulnerability in DMXReady Site Chassis Manager allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2004-2188
|
2008-09-11 04:33 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312366
|
7.5 |
HIGH
|
david_maciejak
|
athena_web_registration
|
athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter.
|
NVD-CWE-Other
|
CVE-2004-1782
|
2008-09-11 04:32 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312367
|
5.0 |
MEDIUM
|
openldap
|
openldap
|
Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service (memory consumption).
|
NVD-CWE-Other
|
CVE-2004-1880
|
2008-09-11 04:32 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312368
|
7.5 |
HIGH
|
apple
|
safari
|
Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "…
|
NVD-CWE-Other
|
CVE-2004-1122
|
2008-09-11 04:29 |
2005-01-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312369
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other…
|
NVD-CWE-Other
|
CVE-2004-0925
|
2008-09-11 04:28 |
2005-01-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312370
|
7.2 |
HIGH
|
gnu
|
mailutils
|
Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2004-0984
|
2008-09-11 04:28 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312371
|
5.0 |
MEDIUM
|
apple
|
quicktime
|
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memo…
|
NVD-CWE-Other
|
CVE-2004-0988
|
2008-09-11 04:28 |
2005-03-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312372
|
7.5 |
HIGH
|
mpg123 suse
|
mpg123 suse_linux
|
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
|
NVD-CWE-Other
|
CVE-2004-0991
|
2008-09-11 04:28 |
2005-01-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312373
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.
|
NVD-CWE-Other
|
CVE-2004-0086
|
2008-09-11 04:25 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312374
|
2.1 |
LOW
|
apple
|
mac_os_x
|
The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerability than CVE-2004-0087.
|
NVD-CWE-Other
|
CVE-2004-0088
|
2008-09-11 04:25 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312375
|
10.0 |
HIGH
|
apple
|
mac_os_x
|
Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.
|
NVD-CWE-Other
|
CVE-2004-0092
|
2008-09-11 04:25 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312376
|
10.0 |
HIGH
|
freebsd
|
freebsd
|
The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets …
|
NVD-CWE-Other
|
CVE-2004-0002
|
2008-09-11 04:24 |
2004-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312377
|
5.0 |
MEDIUM
|
beasts
|
vsftpd
|
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.
|
NVD-CWE-Other
|
CVE-2004-0042
|
2008-09-11 04:24 |
2004-02-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312378
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.
|
NVD-CWE-Other
|
CVE-2003-1220
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312379
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communi…
|
NVD-CWE-Other
|
CVE-2003-1221
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312380
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext …
|
NVD-CWE-Other
|
CVE-2003-1222
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312381
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as d…
|
NVD-CWE-Other
|
CVE-2003-1223
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312382
|
2.1 |
LOW
|
bea
|
weblogic_server
|
Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by…
|
NVD-CWE-Other
|
CVE-2003-1224
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312383
|
2.1 |
LOW
|
bea
|
weblogic_server
|
The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.
|
NVD-CWE-Other
|
CVE-2003-1225
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312384
|
2.1 |
LOW
|
bea
|
weblogic_server
|
BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to…
|
NVD-CWE-Other
|
CVE-2003-1226
|
2008-09-11 04:22 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312385
|
7.5 |
HIGH
|
cisco
|
80-7111-01_for_the_unity-svrx255-1a 80-7112-01_for_the_unity-svrx255-2a
|
Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bu…
|
NVD-CWE-Other
|
CVE-2003-0983
|
2008-09-11 04:21 |
2004-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312386
|
5.0 |
MEDIUM
|
cisco
|
catalyst_6500 catalyst_6500_ws-svc-nam-1 catalyst_6500_ws-svc-nam-2 catalyst_6500_ws-x6380-nam catalyst_7600_ws-svc-nam-1 catalyst_7600_ws-svc-nam-2 catalyst_7600_ws-x6380-nam fi…
|
Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth reque…
|
NVD-CWE-Other
|
CVE-2003-1001
|
2008-09-11 04:21 |
2004-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312387
|
5.0 |
MEDIUM
|
cisco
|
catalyst_6500 catalyst_6500_ws-svc-nam-1 catalyst_6500_ws-svc-nam-2 catalyst_6500_ws-x6380-nam catalyst_7600_ws-svc-nam-1 catalyst_7600_ws-svc-nam-2 catalyst_7600_ws-x6380-nam fi…
|
Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is …
|
NVD-CWE-Other
|
CVE-2003-1002
|
2008-09-11 04:21 |
2004-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312388
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.
|
NVD-CWE-Other
|
CVE-2003-1005
|
2008-09-11 04:21 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312389
|
2.1 |
LOW
|
linux
|
linux_kernel
|
Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).
|
NVD-CWE-Other
|
CVE-2003-0643
|
2008-09-11 04:20 |
2003-07-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312390
|
7.5 |
HIGH
|
trend_micro
|
damage_cleanup_server housecall
|
Multiple buffer overflows in ActiveX controls used by Trend Micro HouseCall 5.5 and 5.7, and Damage Cleanup Server 1.0, allow remote attackers to execute arbitrary code via long parameter strings.
|
NVD-CWE-Other
|
CVE-2003-0646
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312391
|
7.5 |
HIGH
|
cisco
|
ios
|
Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.
|
NVD-CWE-Other
|
CVE-2003-0647
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312392
|
7.2 |
HIGH
|
xpcd
|
xpcd
|
Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2003-0649
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312393
|
5.0 |
MEDIUM
|
netbsd
|
netbsd
|
The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote a…
|
NVD-CWE-Other
|
CVE-2003-0653
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312394
|
7.5 |
HIGH
|
autorespond
|
autorespond
|
Buffer overflow in autorespond may allow remote attackers to execute arbitrary code as the autorespond user via qmail.
|
NVD-CWE-Other
|
CVE-2003-0654
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312395
|
2.1 |
LOW
|
sustainable_softworks
|
ipnetmonitorx ipnetsentryx
|
Sustworks IPNetSentryX and IPNetMonitorX allow local users to sniff network packets via the setuid helper applications (1) RunTCPDump, which calls tcpdump, and (2) RunTCPFlow, which calls tcpflow.
|
NVD-CWE-Other
|
CVE-2003-0670
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312396
|
7.2 |
HIGH
|
jeremy_elson
|
tcpflow
|
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMo…
|
NVD-CWE-Other
|
CVE-2003-0671
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312397
|
7.5 |
HIGH
|
leon_j_breedt
|
pam-pgsql
|
Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled whe…
|
NVD-CWE-Other
|
CVE-2003-0672
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312398
|
5.0 |
MEDIUM
|
cisco
|
webns
|
Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM…
|
NVD-CWE-Other
|
CVE-2003-0677
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312399
|
2.1 |
LOW
|
sgi
|
irix
|
Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allows local users to truncate or overwrite certain files.
|
NVD-CWE-Other
|
CVE-2003-0679
|
2008-09-11 04:20 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312400
|
7.5 |
HIGH
|
sgi
|
irix
|
Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.
|
NVD-CWE-Other
|
CVE-2003-0680
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|