Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 343 977

Количество 343 977

nvd логотип

CVE-2003-0051

около 23 лет назад

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0050

около 23 лет назад

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2003-0049

около 23 лет назад

Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0048

около 23 лет назад

PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0047

около 23 лет назад

SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0046

около 23 лет назад

AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0045

около 23 лет назад

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0044

около 23 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2003-0043

около 23 лет назад

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0042

около 23 лет назад

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2003-0041

около 23 лет назад

Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-0040

около 23 лет назад

SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0039

около 23 лет назад

ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0038

около 23 лет назад

Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2003-0037

около 23 лет назад

Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0036

около 23 лет назад

ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-2003-0035

около 23 лет назад

Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0034

около 23 лет назад

Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0033

около 23 лет назад

Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2003-0032

около 23 лет назад

Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-0051

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.

CVSS2: 5
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0050

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.

CVSS2: 7.5
88%
Высокий
около 23 лет назад
nvd логотип
CVE-2003-0049

Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.

CVSS2: 7.5
1%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0048

PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0047

SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0046

AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0045

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.

CVSS2: 5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0044

Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.

CVSS2: 6.8
27%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0043

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.

CVSS2: 5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0042

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.

CVSS2: 5
56%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0041

Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.

CVSS2: 10
1%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0040

SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.

CVSS2: 7.5
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0039

ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.

CVSS2: 5
4%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0038

Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.

CVSS2: 4.3
11%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0037

Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.

CVSS2: 7.5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0036

ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".

CVSS2: 6.2
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0035

Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.

CVSS2: 7.2
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0034

Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.

CVSS2: 7.2
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0033

Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.

CVSS2: 10
52%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0032

Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.

CVSS2: 5
1%
Низкий
около 23 лет назад

Уязвимостей на страницу