Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 149

Количество 371 149

nvd логотип

CVE-2003-0062

больше 23 лет назад

Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0061

больше 24 лет назад

Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0060

больше 23 лет назад

Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0059

больше 23 лет назад

Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0058

больше 23 лет назад

MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0057

больше 23 лет назад

Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0056

больше 23 лет назад

Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2003-0055

больше 23 лет назад

Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0054

больше 23 лет назад

Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0053

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2003-0052

больше 23 лет назад

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0051

больше 23 лет назад

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0050

больше 23 лет назад

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2003-0049

больше 23 лет назад

Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2003-0048

больше 23 лет назад

PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0047

больше 23 лет назад

SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0046

больше 23 лет назад

AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2003-0045

больше 23 лет назад

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2003-0044

больше 23 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2003-0043

больше 23 лет назад

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2003-0062

Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.

CVSS2: 7.2
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0061

Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.

CVSS2: 7.2
1%
Низкий
больше 24 лет назад
nvd логотип
CVE-2003-0060

Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.

CVSS2: 7.5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0059

Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.

CVSS2: 7.5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0058

MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.

CVSS2: 5
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0057

Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.

CVSS2: 7.5
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0056

Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.

CVSS2: 7.2
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0055

Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.

CVSS2: 7.5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0054

Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0053

Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.

CVSS2: 4.3
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0052

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0051

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0050

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.

CVSS2: 7.5
69%
Средний
больше 23 лет назад
nvd логотип
CVE-2003-0049

Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0048

PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0047

SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0046

AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0045

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0044

Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.

CVSS2: 6.8
9%
Низкий
больше 23 лет назад
nvd логотип
CVE-2003-0043

Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.

CVSS2: 5
4%
Низкий
больше 23 лет назад

Уязвимостей на страницу