Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 344 000

Количество 344 000

nvd логотип

CVE-2003-0284

почти 23 года назад

Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0283

почти 23 года назад

Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-0282

почти 23 года назад

Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2003-0281

почти 23 года назад

Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0280

почти 23 года назад

Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2003-0279

почти 23 года назад

Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2003-0278

почти 23 года назад

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-0277

почти 23 года назад

Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0276

почти 23 года назад

Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2003-0275

почти 23 года назад

SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2003-0274

почти 23 года назад

Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-0273

почти 23 года назад

Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-0272

почти 23 года назад

admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-0271

почти 23 года назад

Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0270

почти 23 года назад

The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.

CVSS2: 7.6
EPSS: Средний
nvd логотип

CVE-2003-0269

почти 23 года назад

Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0268

почти 23 года назад

SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0267

почти 23 года назад

ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0266

почти 23 года назад

Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0265

почти 23 года назад

Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.

CVSS2: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-0284

Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0283

Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

CVSS2: 6.8
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0282

Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.

CVSS2: 2.6
21%
Средний
почти 23 года назад
nvd логотип
CVE-2003-0281

Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.

CVSS2: 4.6
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0280

Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.

CVSS2: 10
11%
Средний
почти 23 года назад
nvd логотип
CVE-2003-0279

Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.

CVSS2: 2.6
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0278

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

CVSS2: 6.8
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0277

Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.

CVSS2: 5
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0276

Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.

CVSS2: 5
16%
Средний
почти 23 года назад
nvd логотип
CVE-2003-0275

SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.

CVSS2: 5.1
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0274

Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.

CVSS2: 10
9%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0273

Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.

CVSS2: 6.8
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0272

admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.

CVSS2: 10
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0271

Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.

CVSS2: 7.5
5%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0270

The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.

CVSS2: 7.6
22%
Средний
почти 23 года назад
nvd логотип
CVE-2003-0269

Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.

CVSS2: 7.2
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0268

SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0267

ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0266

Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.

CVSS2: 7.5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0265

Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.

CVSS2: 6.2
0%
Низкий
почти 23 года назад

Уязвимостей на страницу