|
313551
|
2.1 |
LOW
|
globalscape
|
cuteftp
|
Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.
|
NVD-CWE-Other
|
CVE-2003-1261
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313552
|
5.0 |
MEDIUM
|
brown_bear_software
|
ical
|
ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name.
|
NVD-CWE-Other
|
CVE-2003-1263
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313553
|
5.0 |
MEDIUM
|
d-link longshine_technologie
|
di-614\+ longshine_wireless_ethernet_access_point
|
TFTP server in Longshine Wireless Access Point (WAP) LCS-883R-AC-B, and in D-Link DI-614+ 2.0 which is based on it, allows remote attackers to obtain the WEP secret and gain administrator privileges …
|
NVD-CWE-Other
|
CVE-2003-1264
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313554
|
2.1 |
LOW
|
mozilla netscape
|
mozilla navigator
|
Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
|
NVD-CWE-Other
|
CVE-2003-1265
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313555
|
5.0 |
MEDIUM
|
etype
|
eserv
|
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.
|
NVD-CWE-Other
|
CVE-2003-1266
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313556
|
5.0 |
MEDIUM
|
steve_poulsen
|
guildftpd
|
GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.
|
NVD-CWE-Other
|
CVE-2003-1267
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313557
|
7.5 |
HIGH
|
urlogy
|
a.shop.kart
|
Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive informatio…
|
NVD-CWE-Other
|
CVE-2003-1268
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313558
|
5.0 |
MEDIUM
|
an
|
an-http
|
AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message.
|
NVD-CWE-Other
|
CVE-2003-1269
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313559
|
5.0 |
MEDIUM
|
an
|
an-http
|
AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerabil…
|
NVD-CWE-Other
|
CVE-2003-1270
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313560
|
4.3 |
MEDIUM
|
an
|
an-http
|
Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script.
|
NVD-CWE-Other
|
CVE-2003-1271
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313561
|
5.0 |
MEDIUM
|
microsoft
|
pocket_ie
|
Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.
|
NVD-CWE-Other
|
CVE-2003-1275
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313562
|
4.6 |
MEDIUM
|
nettelephone
|
nettelephone
|
Netfone.exe of NetTelephone 3.5.6 uses weak encryption for user PIN's and stores user account numbers in plaintext in the HKEY_CURRENT_USER\Software\MediaRing.com\SDK\NetTelephone\settings registry k…
|
NVD-CWE-Other
|
CVE-2003-1276
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313563
|
4.3 |
MEDIUM
|
yabb
|
yabb
|
Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information v…
|
NVD-CWE-Other
|
CVE-2003-1277
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313564
|
4.3 |
MEDIUM
|
infopop
|
opentopic
|
Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting a…
|
NVD-CWE-Other
|
CVE-2003-1278
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313565
|
4.6 |
MEDIUM
|
-
|
-
|
S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and…
|
NVD-CWE-Other
|
CVE-2003-1279
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313566
|
5.0 |
MEDIUM
|
eekim
|
cgihtml
|
Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.
|
NVD-CWE-Other
|
CVE-2003-1280
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313567
|
2.1 |
LOW
|
eekim
|
cgihtml
|
cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.
|
NVD-CWE-Other
|
CVE-2003-1281
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313568
|
5.0 |
MEDIUM
|
-
|
-
|
IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE)…
|
NVD-CWE-Other
|
CVE-2003-1282
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313569
|
7.5 |
HIGH
|
kazaa
|
kazaa_media_desktop
|
KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-1283
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313570
|
5.0 |
MEDIUM
|
vserver
|
linux-vserver
|
Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (…
|
NVD-CWE-Other
|
CVE-2003-1288
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313571
|
4.3 |
MEDIUM
|
nukedweb
|
guestbookhost
|
Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when sig…
|
NVD-CWE-Other
|
CVE-2003-1293
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313572
|
2.1 |
LOW
|
redhat suse
|
enterprise_linux suse_linux
|
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."
|
NVD-CWE-Other
|
CVE-2003-1295
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313573
|
5.0 |
MEDIUM
|
-
|
-
|
Easy File Sharing (EFS) Web Server 1.2 stores the (1) option.ini (aka options.ini) file and (2) log directory under the web root with insufficient access control, which allows remote attackers to obt…
|
NVD-CWE-Other
|
CVE-2003-1297
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313574
|
5.0 |
MEDIUM
|
pablo_software_solutions
|
baby_ftp_server
|
Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which …
|
NVD-CWE-Other
|
CVE-2003-1300
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313575
|
2.6 |
LOW
|
-
|
-
|
Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors …
|
NVD-CWE-Other
|
CVE-2003-1306
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313576
|
2.6 |
LOW
|
-
|
-
|
Successful exploitation requires that the RemoveServerHeader option is enabled.
|
NVD-CWE-Other
|
CVE-2003-1306
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313577
|
4.6 |
MEDIUM
|
fvwm
|
fvwm
|
CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.
|
NVD-CWE-Other
|
CVE-2003-1308
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313578
|
6.8 |
MEDIUM
|
-
|
-
|
siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might tric…
|
NVD-CWE-Other
|
CVE-2003-1311
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313579
|
4.3 |
MEDIUM
|
-
|
-
|
siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, …
|
NVD-CWE-Other
|
CVE-2003-1312
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313580
|
7.5 |
HIGH
|
eternalmart
|
mailing_list_manager
|
Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter …
|
NVD-CWE-Other
|
CVE-2003-1313
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313581
|
5.1 |
MEDIUM
|
sonicwall
|
firmware
|
SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including…
|
CWE-399
リソース管理の問題
|
CVE-2003-1320
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313582
|
10.0 |
HIGH
|
atrium_software
|
mercur_mailserver
|
Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (…
|
NVD-CWE-Other
|
CVE-2003-1322
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313583
|
6.8 |
MEDIUM
|
elm_development_group
|
elm
|
Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group …
|
NVD-CWE-Other
|
CVE-2003-1323
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313584
|
4.6 |
MEDIUM
|
elmme-mailer
|
elm_me\+
|
Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the …
|
NVD-CWE-Other
|
CVE-2003-1324
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313585
|
5.2 |
MEDIUM
|
valve_software
|
half-life_cstrike_dedicated_server
|
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemo…
|
NVD-CWE-Other
|
CVE-2003-1325
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313586
|
7.8 |
HIGH
|
washington_university
|
wu-ftpd
|
ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers…
|
NVD-CWE-Other
|
CVE-2003-1329
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313587
|
6.4 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mo…
|
NVD-CWE-Other
|
CVE-2003-1363
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313588
|
3.6 |
LOW
|
ralf_hoffmann
|
worker_filemanager
|
Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information.
|
CWE-264
認可・権限・アクセス制御
|
CVE-2003-1460
|
2008-09-6 05:36 |
2003-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313589
|
7.5 |
HIGH
|
tomi_manninen
|
linuxnode
|
Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0707
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313590
|
7.5 |
HIGH
|
tomi_manninen
|
linuxnode
|
Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2003-0708
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313591
|
7.5 |
HIGH
|
compaq
|
tru64
|
ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2003-0724
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313592
|
7.5 |
HIGH
|
realnetworks
|
helix_universal_server realserver
|
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows…
|
NVD-CWE-Other
|
CVE-2003-0725
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313593
|
10.0 |
HIGH
|
cisco
|
resource_manager resource_manager_essentials ciscoworks_common_management_foundation ciscoworks_cd1
|
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Ad…
|
NVD-CWE-Other
|
CVE-2003-0732
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313594
|
6.8 |
MEDIUM
|
bea
|
liquid_data weblogic_integration weblogic_server
|
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary …
|
NVD-CWE-Other
|
CVE-2003-0733
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313595
|
5.0 |
MEDIUM
|
hp
|
openview
|
Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs,…
|
NVD-CWE-Other
|
CVE-2003-0746
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313596
|
6.8 |
MEDIUM
|
sap
|
internet_transaction_server
|
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~servi…
|
NVD-CWE-Other
|
CVE-2003-0749
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313597
|
7.5 |
HIGH
|
attila-php.net
|
attilaphp
|
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.
|
NVD-CWE-Other
|
CVE-2003-0752
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313598
|
5.0 |
MEDIUM
|
checkpoint
|
firewall-1
|
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP add…
|
NVD-CWE-Other
|
CVE-2003-0757
|
2008-09-6 05:35 |
2003-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313599
|
7.5 |
HIGH
|
digium
|
asterisk
|
Buffer overflow in the get_msg_text of chan_sip.c in the Session Initiation Protocol (SIP) protocol implementation for Asterisk releases before August 15, 2003, allows remote attackers to execute arb…
|
NVD-CWE-Other
|
CVE-2003-0761
|
2008-09-6 05:35 |
2003-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313600
|
7.8 |
HIGH
|
charles_kerr
|
pan
|
Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.
|
NVD-CWE-Other
|
CVE-2003-0855
|
2008-09-6 05:35 |
2003-11-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|