Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 464

Количество 361 464

nvd логотип

CVE-2003-0246

около 23 лет назад

The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2003-0245

около 23 лет назад

Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2003-0244

около 23 лет назад

The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0243

около 23 лет назад

Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0242

около 23 лет назад

IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0241

около 23 лет назад

FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0240

около 23 лет назад

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2003-0239

около 23 лет назад

icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0238

около 23 лет назад

The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0237

около 23 лет назад

The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0236

около 23 лет назад

Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0235

около 23 лет назад

Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0233

больше 23 лет назад

Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2003-0232

почти 23 года назад

Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0231

почти 23 года назад

Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2003-0230

почти 23 года назад

Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0228

около 23 лет назад

Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2003-0227

около 23 лет назад

The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2003-0226

около 23 лет назад

Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2003-0225

около 23 лет назад

The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-0246

The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.

CVSS2: 3.6
1%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0245

Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.

CVSS2: 5
63%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0244

The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.

CVSS2: 5
4%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0243

Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.

CVSS2: 7.5
3%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0242

IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.

CVSS2: 7.5
3%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0241

FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.

CVSS2: 7.5
3%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0240

The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

CVSS2: 10
30%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0239

icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.

CVSS2: 5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0238

The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.

CVSS2: 5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0237

The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.

CVSS2: 7.5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0236

Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.

CVSS2: 7.5
3%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0235

Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.

CVSS2: 7.5
2%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-0233

Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.

CVSS2: 7.5
19%
Средний
больше 23 лет назад
nvd логотип
CVE-2003-0232

Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.

CVSS2: 7.2
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0231

Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.

CVSS2: 5
36%
Средний
почти 23 года назад
nvd логотип
CVE-2003-0230

Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.

CVSS2: 7.2
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-0228

Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.

CVSS2: 7.5
46%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0227

The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.

CVSS2: 5
39%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0226

Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.

CVSS2: 5
43%
Средний
около 23 лет назад
nvd логотип
CVE-2003-0225

The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.

CVSS2: 5
38%
Средний
около 23 лет назад

Уязвимостей на страницу