|
312451
|
5.0 |
MEDIUM
|
mcafee
|
epolicy_orchestrator
|
Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request.
|
NVD-CWE-Other
|
CVE-2003-0610
|
2008-09-11 04:19 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312452
|
4.6 |
MEDIUM
|
zblast
|
zblast
|
Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlier allows local users to execute arbitrary code via the high score file.
|
NVD-CWE-Other
|
CVE-2003-0613
|
2008-09-11 04:19 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312453
|
5.0 |
MEDIUM
|
nokia
|
sgsn_dx200
|
SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.
|
NVD-CWE-Other
|
CVE-2003-0137
|
2008-09-11 04:18 |
2003-03-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312454
|
7.2 |
HIGH
|
mcafee
|
epolicy_orchestrator
|
The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username a…
|
NVD-CWE-Other
|
CVE-2003-0148
|
2008-09-11 04:18 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312455
|
7.5 |
HIGH
|
mcafee
|
epolicy_orchestrator
|
Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.
|
NVD-CWE-Other
|
CVE-2003-0149
|
2008-09-11 04:18 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312456
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a d…
|
NVD-CWE-Other
|
CVE-2003-0171
|
2008-09-11 04:18 |
2003-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312457
|
7.2 |
HIGH
|
xfsdump sgi
|
xfsdump irix
|
xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2003-0173
|
2008-09-11 04:18 |
2003-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312458
|
6.4 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.
|
NVD-CWE-Other
|
CVE-2003-0198
|
2008-09-11 04:18 |
2003-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312459
|
2.1 |
LOW
|
gs-common
|
gs-common
|
ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2003-0207
|
2008-09-11 04:18 |
2003-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312460
|
9.3 |
HIGH
|
cisco
|
catos
|
Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.
|
NVD-CWE-noinfo CWE-287
不適切な認証
|
CVE-2003-0216
|
2008-09-11 04:18 |
2003-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312461
|
7.5 |
HIGH
|
happycgi
|
happymall
|
Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.
|
NVD-CWE-Other
|
CVE-2003-0243
|
2008-09-11 04:18 |
2003-05-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312462
|
7.5 |
HIGH
|
kde
|
kopete
|
The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2003-0256
|
2008-09-11 04:18 |
2003-05-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312463
|
4.6 |
MEDIUM
|
fuzz
|
fuzz
|
fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2003-0261
|
2008-09-11 04:18 |
2003-05-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312464
|
7.5 |
HIGH
|
apple kde redhat turbolinux
|
safari konqueror_embedded kde linux turbolinux_server turbolinux_workstation
|
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle atta…
|
NVD-CWE-Other
|
CVE-2003-0370
|
2008-09-11 04:18 |
2003-06-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312465
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server
|
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters.
|
NVD-CWE-Other
|
CVE-2003-0422
|
2008-09-11 04:18 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312466
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server
|
parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.
|
NVD-CWE-Other
|
CVE-2003-0423
|
2008-09-11 04:18 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312467
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server
|
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the…
|
NVD-CWE-Other
|
CVE-2003-0424
|
2008-09-11 04:18 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312468
|
5.0 |
MEDIUM
|
apple
|
darwin_streaming_server
|
Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request.
|
NVD-CWE-Other
|
CVE-2003-0425
|
2008-09-11 04:18 |
2003-08-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312469
|
7.2 |
HIGH
|
apc
|
apcupsd
|
Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.
|
NVD-CWE-Other
|
CVE-2003-0099
|
2008-09-11 04:17 |
2003-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312470
|
1.2 |
LOW
|
jmcce mandrakesoft
|
jmcce mandrake_linux
|
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2002-2001
|
2008-09-11 04:16 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312471
|
7.2 |
HIGH
|
qnx
|
rtos
|
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-…
|
NVD-CWE-Other
|
CVE-2002-2041
|
2008-09-11 04:16 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312472
|
7.5 |
HIGH
|
mozilla netscape
|
mozilla navigator
|
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values…
|
NVD-CWE-Other
|
CVE-2002-2061
|
2008-09-11 04:16 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312473
|
7.5 |
HIGH
|
bea
|
weblogic_server
|
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Se…
|
NVD-CWE-Other
|
CVE-2002-2141
|
2008-09-11 04:16 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312474
|
7.5 |
HIGH
|
bea
|
weblogic_integration weblogic_server
|
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through …
|
NVD-CWE-Other
|
CVE-2002-2142
|
2008-09-11 04:16 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312475
|
4.3 |
MEDIUM
|
andrey_cherezov
|
acweb
|
Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL.
|
NVD-CWE-Other
|
CVE-2002-2171
|
2008-09-11 04:16 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312476
|
2.6 |
LOW
|
bea
|
weblogic_server
|
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to …
|
NVD-CWE-Other
|
CVE-2002-2177
|
2008-09-11 04:16 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312477
|
7.5 |
HIGH
|
benjamin_lefevre
|
dobermann_forum
|
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) in…
|
NVD-CWE-Other
|
CVE-2002-2200
|
2008-09-11 04:16 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312478
|
5.0 |
MEDIUM
|
mike_spice
|
my_classifieds
|
Directory traversal vulnerability in Mike Spice's My Classifieds (classifieds.cgi) before 1.3 allows remote attackers to overwrite arbitrary files via the category parameter.
|
NVD-CWE-Other
|
CVE-2002-1600
|
2008-09-11 04:15 |
2002-01-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312479
|
5.0 |
MEDIUM
|
mywebserver
|
mywebserver
|
MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-1897
|
2008-09-11 04:15 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312480
|
5.0 |
MEDIUM
|
ibm
|
websphere_caching_proxy_server
|
IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version nu…
|
NVD-CWE-Other
|
CVE-2002-1169
|
2008-09-11 04:14 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312481
|
4.6 |
MEDIUM
|
cisco
|
unity_server
|
The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international cal…
|
NVD-CWE-Other
|
CVE-2002-1189
|
2008-09-11 04:14 |
2002-10-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312482
|
2.1 |
LOW
|
tkmail
|
tkmail
|
tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2002-1193
|
2008-09-11 04:14 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312483
|
7.5 |
HIGH
|
netbsd
|
netbsd
|
Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.
|
NVD-CWE-Other
|
CVE-2002-1194
|
2008-09-11 04:14 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312484
|
7.5 |
HIGH
|
compaq
|
tru64
|
Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2002-1202
|
2008-09-11 04:14 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312485
|
5.0 |
MEDIUM
|
netscape
|
communicator
|
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail passwo…
|
NVD-CWE-Other
|
CVE-2002-1204
|
2008-09-11 04:14 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312486
|
5.0 |
MEDIUM
|
radiobird_software
|
webserver_4_all
|
Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-1212
|
2008-09-11 04:14 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312487
|
5.0 |
MEDIUM
|
radiobird_software
|
webserver_4_all
|
Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".…
|
NVD-CWE-Other
|
CVE-2002-1213
|
2008-09-11 04:14 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312488
|
10.0 |
HIGH
|
linux-ha
|
heartbeat
|
Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 69…
|
NVD-CWE-Other
|
CVE-2002-1215
|
2008-09-11 04:14 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312489
|
7.1 |
HIGH
|
cisco
|
catos
|
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.
|
CWE-119
バッファエラー
|
CVE-2002-1222
|
2008-09-11 04:14 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312490
|
2.1 |
LOW
|
caldera
|
unixware openunix
|
SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc.
|
NVD-CWE-Other
|
CVE-2002-1231
|
2008-09-11 04:14 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312491
|
7.2 |
HIGH
|
abuse
|
abuse
|
Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument.
|
NVD-CWE-Other
|
CVE-2002-1250
|
2008-09-11 04:14 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312492
|
5.0 |
MEDIUM
|
peoplesoft
|
peopletools
|
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fie…
|
NVD-CWE-Other
|
CVE-2002-1252
|
2008-09-11 04:14 |
2003-02-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312493
|
7.5 |
HIGH
|
jacques_gelinas
|
linuxconf
|
The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a…
|
NVD-CWE-Other
|
CVE-2002-1278
|
2008-09-11 04:14 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312494
|
7.2 |
HIGH
|
masqmail
|
masqmail
|
Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option).
|
NVD-CWE-Other
|
CVE-2002-1279
|
2008-09-11 04:14 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312495
|
5.0 |
MEDIUM
|
iss
|
realsecure_event_collector
|
Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).
|
NVD-CWE-Other
|
CVE-2002-1280
|
2008-09-11 04:14 |
2002-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312496
|
7.2 |
HIGH
|
suse
|
suse_linux
|
runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.
|
NVD-CWE-Other
|
CVE-2002-1285
|
2008-09-11 04:14 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312497
|
7.5 |
HIGH
|
smb2www
|
smb2www
|
Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2002-1342
|
2008-09-11 04:14 |
2002-12-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312498
|
5.0 |
MEDIUM
|
per_magne_knutsen
|
cartman
|
Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product prices by changing the price parameter.
|
NVD-CWE-Other
|
CVE-2002-1352
|
2008-09-11 04:14 |
2003-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312499
|
7.5 |
HIGH
|
openldap
|
openldap
|
OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges.
|
NVD-CWE-Other
|
CVE-2002-1379
|
2008-09-11 04:14 |
2003-01-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312500
|
2.1 |
LOW
|
debian
|
internet_message
|
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwage…
|
NVD-CWE-Other
|
CVE-2002-1395
|
2008-09-11 04:14 |
2003-01-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|