Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 608

Количество 307 608

nvd логотип

CVE-2003-0459

около 22 лет назад

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0458

около 22 лет назад

Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0456

около 22 лет назад

VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0455

около 22 лет назад

The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0454

около 22 лет назад

Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0453

около 22 лет назад

traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-0452

около 22 лет назад

Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0451

около 22 лет назад

Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0450

около 22 лет назад

Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0449

около 22 лет назад

Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0448

около 22 лет назад

Portmon 1.7 and possibly earlier versions allows local users to read and write arbitrary files via the (1) -c (host file) or (2) -l (log file) command line options.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2003-0447

около 22 лет назад

The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2003-0446

около 22 лет назад

Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2003-0445

около 22 лет назад

Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0444

больше 21 года назад

Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0442

около 22 лет назад

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2003-0441

больше 21 года назад

Multiple buffer overflows in Orville Write (orville-write) 2.53 and earlier allow local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0440

около 22 лет назад

The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0439

больше 8 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none

EPSS: Низкий
nvd логотип

CVE-2003-0438

около 22 лет назад

eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 1.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-0459

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

CVSS2: 5
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0458

Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.

CVSS2: 4.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0456

VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0455

The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.

CVSS2: 4.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0454

Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.

CVSS2: 7.2
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0453

traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.

CVSS2: 10
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0452

Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."

CVSS2: 4.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0451

Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.

CVSS2: 4.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0450

Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow.

CVSS2: 7.5
3%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0449

Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.

CVSS2: 4.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0448

Portmon 1.7 and possibly earlier versions allows local users to read and write arbitrary files via the (1) -c (host file) or (2) -l (log file) command line options.

CVSS2: 3.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0447

The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.

CVSS2: 5.1
30%
Средний
около 22 лет назад
nvd логотип
CVE-2003-0446

Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.

CVSS2: 4.3
43%
Средний
около 22 лет назад
nvd логотип
CVE-2003-0445

Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.

CVSS2: 7.5
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0444

Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-0442

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

CVSS2: 4.3
31%
Средний
около 22 лет назад
nvd логотип
CVE-2003-0441

Multiple buffer overflows in Orville Write (orville-write) 2.53 and earlier allow local users to gain privileges.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2003-0440

The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.6
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2003-0439

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2003. Notes: none

больше 8 лет назад
nvd логотип
CVE-2003-0438

eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 1.2
0%
Низкий
около 22 лет назад

Уязвимостей на страницу