Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0578 1 Ibm 1 U2 Universe 2016-10-18 4.6 MEDIUM N/A
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.
CVE-2003-0536 1 Phpsysinfo 1 Phpsysinfo 2016-10-18 3.6 LOW N/A
Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters.
CVE-2003-0562 1 Novell 1 Netware 2016-10-18 5.0 MEDIUM N/A
Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.
CVE-2003-0561 1 Iglooftp 1 Iglooftp Pro 2016-10-18 7.5 HIGH N/A
Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.
CVE-2003-0560 1 Virtual Programming 1 Vp-asp 2016-10-18 10.0 HIGH N/A
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.
CVE-2003-0559 1 Phpforum 1 Phpforum 2016-10-18 7.5 HIGH N/A
mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.
CVE-2003-0558 1 Leapware 1 Leapftp 2016-10-18 7.5 HIGH N/A
Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.
CVE-2003-0556 1 Polycom 3 Mgc-100, Mgc-25, Mgc-50 2016-10-18 5.0 MEDIUM N/A
Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.
CVE-2003-0555 1 Imagemagick 1 Imagemagick 2016-10-18 7.5 HIGH N/A
ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability.
CVE-2003-0478 5 Andromede, Bahamut, Daniel Moss and 2 more 5 Adromedeircd, Ircd, Methane and 2 more 2016-10-18 10.0 HIGH N/A
Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.
CVE-2003-0453 1 Ehud Gavron 1 Traceroute-nanog 2016-10-18 10.0 HIGH N/A
traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow.
CVE-2003-0480 1 Vmware 1 Workstation 2016-10-18 3.7 LOW N/A
VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."
CVE-2003-0520 1 Cerulean Studios 1 Trillian 2016-10-18 5.0 MEDIUM N/A
Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.
CVE-2003-0524 1 Knoppix 1 Knoppix 2016-10-18 6.2 MEDIUM N/A
Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.
CVE-2003-0523 1 Early Impact 1 Productcart 2016-10-18 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.
CVE-2003-0522 1 Early Impact 1 Productcart 2016-10-18 10.0 HIGH N/A
Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.
CVE-2003-0521 1 Cpanel 1 Cpanel 2016-10-18 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.
CVE-2003-0510 1 Ezbounce 1 Ezbounce 2016-10-18 7.5 HIGH N/A
Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.
CVE-2003-0508 1 Adobe 1 Acrobat Reader 2016-10-18 7.5 HIGH N/A
Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.
CVE-2003-0507 1 Microsoft 1 Windows 2000 2016-10-18 7.5 HIGH N/A
Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR," and possibly other statements, which causes LSASS.EXE to crash.
CVE-2003-0506 1 Microsoft 1 Netmeeting 2016-10-18 5.0 MEDIUM N/A
Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
CVE-2003-0505 1 Microsoft 1 Netmeeting 2016-10-18 5.0 MEDIUM N/A
Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.
CVE-2003-0504 1 Phpgroupware 1 Phpgroupware 2016-10-18 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module.
CVE-2003-0503 1 Microsoft 1 Windows 2000 2016-10-18 7.5 HIGH N/A
Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.
CVE-2003-0493 1 Snitz Communications 1 Snitz Forums 2000 2016-10-18 10.0 HIGH N/A
Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.
CVE-2003-0491 1 Mytutorials 1 Tutorials 2016-10-18 7.5 HIGH N/A
The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.
CVE-2003-0490 1 Dantz 1 Retrospect Client 2016-10-18 7.2 HIGH N/A
The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code.
CVE-2003-0485 1 Progress 1 4gl Compiler 2016-10-18 4.6 MEDIUM N/A
Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.
CVE-2003-0484 1 Phpbb Group 1 Phpbb 2016-10-18 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.
CVE-2003-0482 1 Gero Kohnert 1 Tutos 2016-10-18 7.5 HIGH N/A
TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.
CVE-2003-0481 1 Gero Kohnert 1 Tutos 2016-10-18 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.
CVE-2003-0477 1 Wzdftpd 1 Wzdftpd 2016-10-18 5.0 MEDIUM N/A
wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.
CVE-2003-0475 1 Ashley Brown 1 Iweb Server 2016-10-18 5.0 MEDIUM N/A
Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.
CVE-2003-0474 1 Ashley Brown 1 Iweb Server 2016-10-18 5.0 MEDIUM N/A
Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.
CVE-2003-0471 1 Alt-n 1 Webadmin 2016-10-18 7.5 HIGH N/A
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.
CVE-2003-0467 1 Linux 1 Linux Kernel 2016-10-18 5.0 MEDIUM N/A
Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC is enabled, or the ip_nat_ftp or ip_nat_irc modules are loaded, allows remote attackers to cause a denial of service (crash) in systems using NAT, possibly due to an integer signedness error.
CVE-2003-0455 1 Imagemagick 1 Libmagick Library 2016-10-18 4.6 MEDIUM N/A
The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.
CVE-2003-0479 1 Affordable Web Space Design 1 Affordable Web Space Design Webbbs 2016-10-18 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the guestbook for WebBBS allows remote attackers to insert arbitrary web script via the (1) Name, (2) Email, or (3) Message fields.
CVE-2003-0382 2 Debian, Michael Jennings 2 Debian Linux, Eterm 2016-10-18 4.6 MEDIUM N/A
Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.
CVE-2003-0404 1 Vignette 3 Content Suite, Storyserver, Vignette 2016-10-18 4.3 MEDIUM N/A
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.
CVE-2003-0385 1 Debian 1 Debian Linux 2016-10-18 7.2 HIGH N/A
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.
CVE-2003-0399 1 Vignette 3 Content Suite, Storyserver, Vignette 2016-10-18 6.4 MEDIUM N/A
Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.
CVE-2003-0405 1 Vignette 3 Content Suite, Storyserver, Vignette 2016-10-18 5.0 MEDIUM N/A
Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.
CVE-2003-0418 1 Linux 1 Linux Kernel 2016-10-18 5.0 MEDIUM N/A
The Linux 2.0 kernel IP stack does not properly calculate the size of an ICMP citation, which causes it to include portions of unauthorized memory in ICMP error responses.
CVE-2003-0398 1 Vignette 3 Content Suite, Storyserver, Vignette 2016-10-18 7.5 HIGH N/A
Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.
CVE-2003-0397 1 Sharman Networks 1 Kazaa 2016-10-18 7.5 HIGH N/A
Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list of supernodes, aka "Packet 0' death."
CVE-2003-0406 1 Palmvnc 1 Palmvnc 2016-10-18 7.2 HIGH N/A
PalmVNC 1.40 and earlier stores passwords in plaintext in the PalmVNCDB, which is backed up to PCs that the Palm is synchronized with, which could allow attackers to gain privileges.
CVE-2003-0388 1 Andrew Morgan 1 Linux Pam 2016-10-18 4.6 MEDIUM N/A
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.
CVE-2003-0407 1 Gnome 1 Batalla Naval 2016-10-18 10.0 HIGH N/A
Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.
CVE-2003-0390 1 James Theiler 1 Opt 2016-10-18 4.6 MEDIUM N/A
Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi.