|
312401
|
7.5 |
HIGH
|
redhat
|
enterprise_linux
|
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number…
|
NVD-CWE-Other
|
CVE-2003-0689
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312402
|
7.2 |
HIGH
|
ibm
|
aix
|
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
|
NVD-CWE-Other
|
CVE-2003-0697
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312403
|
7.5 |
HIGH
|
nicolas_boullis
|
mah-jong
|
Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0705
|
2008-09-11 04:20 |
2003-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312404
|
5.0 |
MEDIUM
|
nicolas_boullis
|
mah-jong
|
Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).
|
NVD-CWE-Other
|
CVE-2003-0706
|
2008-09-11 04:20 |
2003-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312405
|
7.5 |
HIGH
|
whois
|
whois
|
Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.
|
NVD-CWE-Other
|
CVE-2003-0709
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312406
|
7.5 |
HIGH
|
gkrellm
|
gkrellm
|
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0723
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312407
|
10.0 |
HIGH
|
cisco
|
resource_manager resource_manager_essentials ciscoworks_common_management_foundation ciscoworks_cd1
|
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly in…
|
NVD-CWE-Other
|
CVE-2003-0731
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312408
|
10.0 |
HIGH
|
padl_software
|
pam_ldap
|
Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the …
|
NVD-CWE-Other
|
CVE-2003-0734
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312409
|
10.0 |
HIGH
|
castle_rock_computing
|
snmpc
|
SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.
|
NVD-CWE-Other
|
CVE-2003-0745
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312410
|
7.5 |
HIGH
|
py-membres
|
py-membres
|
secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.
|
NVD-CWE-Other
|
CVE-2003-0750
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312411
|
7.5 |
HIGH
|
py-membres
|
py-membres
|
SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.
|
NVD-CWE-Other
|
CVE-2003-0751
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312412
|
5.0 |
MEDIUM
|
newsphp
|
newsphp
|
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.
|
NVD-CWE-Other
|
CVE-2003-0753
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312413
|
7.5 |
HIGH
|
newsphp
|
newsphp
|
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
|
NVD-CWE-Other
|
CVE-2003-0754
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312414
|
10.0 |
HIGH
|
gtkftpd
|
gtkftp
|
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.
|
NVD-CWE-Other
|
CVE-2003-0755
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312415
|
5.0 |
MEDIUM
|
sitebuilder
|
sitebuilder
|
Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.
|
NVD-CWE-Other
|
CVE-2003-0756
|
2008-09-11 04:20 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312416
|
7.5 |
HIGH
|
foxweb
|
foxweb
|
Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).
|
NVD-CWE-Other
|
CVE-2003-0762
|
2008-09-11 04:20 |
2003-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312417
|
7.5 |
HIGH
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.
|
NVD-CWE-Other
|
CVE-2003-0774
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312418
|
5.0 |
MEDIUM
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of s…
|
NVD-CWE-Other
|
CVE-2003-0775
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312419
|
7.5 |
HIGH
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.
|
NVD-CWE-Other
|
CVE-2003-0776
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312420
|
5.0 |
MEDIUM
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of ser…
|
NVD-CWE-Other
|
CVE-2003-0777
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312421
|
5.0 |
MEDIUM
|
sane
|
sane sane-backend
|
saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption…
|
NVD-CWE-Other
|
CVE-2003-0778
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312422
|
7.5 |
HIGH
|
digium
|
asterisk
|
SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.
|
NVD-CWE-Other
|
CVE-2003-0779
|
2008-09-11 04:20 |
2003-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312423
|
10.0 |
HIGH
|
ibm
|
aix
|
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, …
|
NVD-CWE-Other
|
CVE-2003-0784
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312424
|
7.5 |
HIGH
|
brian_bassett
|
ipmasq
|
ipmasq before 3.5.12, in certain configurations, may forward packets to the external interface even if the packets are not associated with an established connection, which could allow remote attacker…
|
NVD-CWE-Other
|
CVE-2003-0785
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312425
|
10.0 |
HIGH
|
openbsd
|
openssh
|
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote att…
|
NVD-CWE-Other
|
CVE-2003-0786
|
2008-09-11 04:20 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312426
|
7.5 |
HIGH
|
openbsd
|
openssh
|
The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.
|
NVD-CWE-Other
|
CVE-2003-0787
|
2008-09-11 04:20 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312427
|
4.3 |
MEDIUM
|
nokia
|
electronic_documentation
|
Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that co…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2003-0801
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312428
|
5.0 |
MEDIUM
|
nokia
|
electronic_documentation
|
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a locati…
|
NVD-CWE-Other
|
CVE-2003-0802
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312429
|
7.5 |
HIGH
|
nokia
|
electronic_documentation
|
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.
|
NVD-CWE-Other
|
CVE-2003-0803
|
2008-09-11 04:20 |
2003-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312430
|
5.0 |
MEDIUM
|
apple freebsd openbsd
|
mac_os_x mac_os_x_server freebsd openbsd
|
The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starv…
|
NVD-CWE-Other
|
CVE-2003-0804
|
2008-09-11 04:20 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312431
|
4.6 |
MEDIUM
|
marbles
|
marbles
|
Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2003-0830
|
2008-09-11 04:20 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312432
|
5.0 |
MEDIUM
|
webfs
|
webfs
|
Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header.
|
NVD-CWE-Other
|
CVE-2003-0832
|
2008-09-11 04:20 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312433
|
7.5 |
HIGH
|
webfs
|
webfs
|
Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname.
|
NVD-CWE-Other
|
CVE-2003-0833
|
2008-09-11 04:20 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312434
|
5.0 |
MEDIUM
|
gnu washington_university
|
fileutils wu-ftpd
|
An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited v…
|
NVD-CWE-Other
|
CVE-2003-0853
|
2008-09-11 04:20 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312435
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."
|
NVD-CWE-Other
|
CVE-2003-0871
|
2008-09-11 04:20 |
2003-11-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312436
|
7.5 |
HIGH
|
minimalist
|
minimalist
|
Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2003-0902
|
2008-09-11 04:20 |
2004-02-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312437
|
4.6 |
MEDIUM
|
omega-rpg
|
omega-rpg
|
Buffer overflow in omega-rpg 0.90 allows local users to execute arbitrary code via a long (1) command line or (2) environment variable.
|
NVD-CWE-Other
|
CVE-2003-0932
|
2008-09-11 04:20 |
2003-12-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312438
|
4.6 |
MEDIUM
|
conquest
|
conquest
|
Buffer overflow in conquest 7.2 and earlier may allow a local user to execute arbitrary code via a long environment variable.
|
NVD-CWE-Other
|
CVE-2003-0933
|
2008-09-11 04:20 |
2003-12-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312439
|
7.5 |
HIGH
|
mnogosearch
|
mnogosearch
|
Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.
|
NVD-CWE-Other
|
CVE-2003-0436
|
2008-09-11 04:19 |
2003-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312440
|
7.5 |
HIGH
|
mnogosearch
|
mnogosearch
|
Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.
|
NVD-CWE-Other
|
CVE-2003-0437
|
2008-09-11 04:19 |
2003-07-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312441
|
7.5 |
HIGH
|
cistron
|
radius_daemon
|
Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is…
|
NVD-CWE-Other
|
CVE-2003-0450
|
2008-09-11 04:19 |
2003-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312442
|
7.5 |
HIGH
|
teapop
|
teapop
|
SQL injection vulnerabilities in the (1) PostgreSQL or (2) MySQL authentication modules for teapop 0.3.5 and earlier allow attackers to execute arbitrary SQL and possibly gain privileges.
|
NVD-CWE-Other
|
CVE-2003-0515
|
2008-09-11 04:19 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312443
|
7.5 |
HIGH
|
gert_doering
|
mgetty
|
cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller …
|
NVD-CWE-Other
|
CVE-2003-0516
|
2008-09-11 04:19 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312444
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
The screen saver in MacOS X allows users with physical access to cause the screen saver to crash and gain access to the underlying session via a large number of characters in the password field, poss…
|
NVD-CWE-Other
|
CVE-2003-0518
|
2008-09-11 04:19 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312445
|
7.2 |
HIGH
|
xblockout
|
xbl
|
Buffer overflow in xbl 1.0k and earlier allows local users to gain privileges via a long -display command line option.
|
NVD-CWE-Other
|
CVE-2003-0535
|
2008-09-11 04:19 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312446
|
7.5 |
HIGH
|
mozart
|
mozart
|
The mailcap file for mozart 1.2.5 and earlier causes Oz applications to be passed to the Oz interpreter, which allows remote attackers to execute arbitrary Oz programs in a MIME-aware client program.
|
NVD-CWE-Other
|
CVE-2003-0538
|
2008-09-11 04:19 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312447
|
7.2 |
HIGH
|
sgi
|
irix
|
Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables…
|
NVD-CWE-Other
|
CVE-2003-0574
|
2008-09-11 04:19 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312448
|
5.0 |
MEDIUM
|
sgi
|
irix
|
Unknown vulnerability in the NFS daemon (nfsd) in SGI IRIX 6.5.19f and earlier allows remote attackers to cause a denial of service (kernel panic) via certain packets that cause XDR decoding errors, …
|
NVD-CWE-Other
|
CVE-2003-0576
|
2008-09-11 04:19 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312449
|
7.5 |
HIGH
|
mpg123
|
mpg123
|
mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which creates a negative frame size.
|
NVD-CWE-Other
|
CVE-2003-0577
|
2008-09-11 04:19 |
2003-08-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312450
|
4.6 |
MEDIUM
|
cvsup sup
|
cvsup-mirror sup
|
sup 1.8 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2003-0606
|
2008-09-11 04:19 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|