Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2003-1166

больше 22 лет назад

Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1165

больше 22 лет назад

Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1164

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1163

больше 22 лет назад

hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1162

больше 22 лет назад

index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1161

больше 22 лет назад

exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-1160

почти 23 года назад

FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-1159

почти 23 года назад

Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1158

больше 22 лет назад

Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1157

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1156

больше 22 лет назад

Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-1155

больше 22 лет назад

X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-1154

больше 22 лет назад

MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1153

больше 22 лет назад

byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1152

больше 22 лет назад

WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1151

почти 23 года назад

Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1150

почти 23 года назад

Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1149

почти 23 года назад

Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1148

почти 23 года назад

Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1147

больше 22 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0955. Reason: This candidate is a duplicate of CVE-2003-0955. Notes: All CVE users should reference CVE-2003-0955 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-1166

Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.

CVSS2: 5
7%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1165

Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.

CVSS2: 5
6%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1164

Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.

CVSS2: 4.3
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1163

hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1162

index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.

CVSS2: 5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1161

exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.

CVSS2: 7.2
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1160

FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).

CVSS2: 10
5%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1159

Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.

CVSS2: 5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1158

Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.

CVSS2: 5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1157

Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.

CVSS2: 4.3
4%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1156

Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1155

X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1154

MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1153

byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1152

WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1151

Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.

CVSS2: 4.3
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1150

Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.

CVSS2: 7.5
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1149

Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page.

CVSS2: 4.3
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1148

Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.

CVSS2: 7.5
9%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1147

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0955. Reason: This candidate is a duplicate of CVE-2003-0955. Notes: All CVE users should reference CVE-2003-0955 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 22 лет назад

Уязвимостей на страницу