Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2003-1146

около 23 лет назад

Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1145

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-1144

больше 22 лет назад

Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-1143

почти 23 года назад

Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1142

больше 22 лет назад

Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-1141

больше 22 лет назад

Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2003-1140

почти 23 года назад

Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2003-1139

почти 23 года назад

Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1138

почти 23 года назад

The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1137

почти 23 года назад

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1136

почти 23 года назад

Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-1135

больше 22 лет назад

Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2003-1134

больше 22 лет назад

Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2003-1133

больше 22 лет назад

Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2003-1132

больше 22 лет назад

The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-1131

больше 22 лет назад

PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1130

больше 22 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-1071. Reason: This candidate is a duplicate of CVE-2003-1071. Notes: All CVE users should reference CVE-2003-1071 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2003-1129

больше 22 лет назад

Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2003-1128

больше 22 лет назад

XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-1127

больше 22 лет назад

Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-1146

Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

CVSS2: 6.8
3%
Низкий
около 23 лет назад
nvd логотип
CVE-2003-1145

Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.

CVSS2: 6.8
4%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1144

Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.

CVSS2: 10
7%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1143

Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.

CVSS2: 7.5
3%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1142

Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.

CVSS2: 10
6%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1141

Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.

CVSS2: 7.5
68%
Средний
больше 22 лет назад
nvd логотип
CVE-2003-1140

Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.

CVSS2: 10
6%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1139

Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.

CVSS2: 5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1138

The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).

CVSS2: 5
5%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1137

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

CVSS2: 5
7%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1136

Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.

CVSS2: 4.3
5%
Низкий
почти 23 года назад
nvd логотип
CVE-2003-1135

Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

CVSS2: 2.6
5%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1134

Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.

CVSS2: 2.1
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1133

Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1132

The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1131

PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1130

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-1071. Reason: This candidate is a duplicate of CVE-2003-1071. Notes: All CVE users should reference CVE-2003-1071 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 22 лет назад
nvd логотип
CVE-2003-1129

Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.

CVSS2: 2.6
8%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1128

XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2003-1127

Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.

CVSS2: 5
2%
Низкий
больше 22 лет назад

Уязвимостей на страницу