Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0602 1 Mozilla 1 Bugzilla 2008-09-05 6.8 MEDIUM N/A
Multiple cross-site scripting vulnerabilities (XSS) in Bugzilla 2.16.x before 2.16.3 and 2.17.x before 2.17.4 allow remote attackers to insert arbitrary HTML or web script via (1) multiple default German and Russian HTML templates or (2) ALT and NAME attributes in AREA tags as used by the GraphViz graph generation feature for local dependency graphs.
CVE-2003-0603 1 Mozilla 1 Bugzilla 2008-09-05 2.1 LOW N/A
Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.
CVE-2003-0360 1 Debian 1 Debian Linux 2008-09-05 7.5 HIGH N/A
Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.
CVE-2003-0611 1 Xtokkaetama 1 Xtokkaetama 2008-09-05 4.6 MEDIUM N/A
Multiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line argument or (2) XTOKKAETAMADIR environment variable.
CVE-2003-0438 1 Yuuichi Teranishi 1 Eldav 2008-09-05 1.2 LOW N/A
eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
CVE-2003-0359 1 Stichting Mathematisch Centrum 1 Nethack 2008-09-05 4.6 MEDIUM N/A
nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.
CVE-2003-0593 1 Opera Software 1 Opera Web Browser 2008-09-05 7.5 HIGH N/A
Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
CVE-2003-0355 2 Apple, Kde 2 Safari, Konqueror Embedded 2008-09-05 5.0 MEDIUM N/A
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
CVE-2003-0445 1 Webfs 1 Webfs 2008-09-05 7.5 HIGH N/A
Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.
CVE-2003-0451 1 Xblockout 1 Xbl 2008-09-05 4.6 MEDIUM N/A
Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.
CVE-2003-0537 1 Daiki Ueno 1 Liece Emacs Irc Client 2008-09-05 4.6 MEDIUM N/A
The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.
CVE-2003-0514 1 Apple 1 Safari 2008-09-05 7.5 HIGH N/A
Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
CVE-2003-0636 1 Novell 1 Ichain 2008-09-05 7.5 HIGH N/A
Novell iChain 2.2 before Support Pack 1 does not properly verify that URL redirects match the DNS name of an accelerator, which allows attackers to redirect URLs to malicious web sites.
CVE-2003-0637 1 Novell 1 Ichain 2008-09-05 5.0 MEDIUM N/A
Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.
CVE-2003-0426 1 Apple 1 Darwin Streaming Server 2008-09-05 10.0 HIGH N/A
The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.
CVE-2003-0640 1 Bea 1 Weblogic Server 2008-09-05 10.0 HIGH N/A
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.
CVE-2003-0389 1 Rsa 1 Ace Agent 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the secure redirect function of RSA ACE/Agent 5.0 for Windows, and 5.x for Web, allows remote attackers to insert arbitrary web script and possibly cause users to enter a passphrase via a GET request containing the script.
CVE-2003-0316 1 Fourelle Venturi Wireless 1 Venturi Client 2008-09-05 5.0 MEDIUM N/A
Venturi Client before 2.2, as used in certain Fourelle and Venturi Wireless products, can be used as an open proxy for various protocols, including an open relay for SMTP, which allows it to be abused by spammers.
CVE-2003-0644 1 Johannes Sixt 1 Kdbg 2008-09-05 4.6 MEDIUM N/A
Kdbg 1.1.0 through 1.2.8 does not check permissions of the .kdbgrc file, which allows local users to execute arbitrary commands.
CVE-2003-0452 1 Gunnar Ritter 1 Osh 2008-09-05 4.6 MEDIUM N/A
Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."
CVE-2003-0500 1 Proftpd Project 1 Proftpd 2008-09-05 10.0 HIGH N/A
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
CVE-2003-0651 1 Mod Mylo 1 Mod Mylo 2008-09-05 7.5 HIGH N/A
Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
CVE-2003-0454 1 Joe Rumsey 1 Xgalaga 2008-09-05 7.2 HIGH N/A
Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.
CVE-2003-0381 1 Norman Ramsey 1 Noweb 2008-09-05 2.1 LOW N/A
Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script.
CVE-2003-0458 1 Hp 1 Nonstop Seeview Server Gateway 2008-09-05 4.6 MEDIUM N/A
Unknown vulnerability in HP NonStop Server D40.00 through D48.03, and G01.00 through G06.20, allows local users to gain additional privileges.
CVE-2003-0657 1 Phpgroupware 1 Phpgroupware 2008-09-05 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct unauthorized database actions.
CVE-2003-0421 1 Apple 1 Darwin Streaming Server 2008-09-05 10.0 HIGH N/A
Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.
CVE-2003-0322 1 Colten Edwards 1 Bitchx 2008-09-05 5.0 MEDIUM N/A
Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).
CVE-2003-0517 1 Gert Doering 1 Mgetty 2008-09-05 2.1 LOW N/A
faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.
CVE-2003-0380 1 Atftpd 1 Atftpd 2008-09-05 7.5 HIGH N/A
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.
CVE-2003-0328 1 Epic 1 Epic4 2008-09-05 7.5 HIGH N/A
EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.
CVE-2003-0362 1 Debian 1 Debian Linux 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.
CVE-2003-0378 1 Apple 1 Mac Os X 2008-09-05 7.5 HIGH N/A
The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.
CVE-2003-0683 1 Sgi 1 Irix 2008-09-05 7.5 HIGH N/A
NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.
CVE-2003-0340 1 Demarc Security 1 Puresecure 2008-09-05 7.5 HIGH N/A
Demarc Puresecure 1.6 stores authentication information for the logging server in plaintext, which allows attackers to steal login names and passwords to gain privileges.
CVE-2003-0489 1 Michael C. Toren 1 Tcptraceroute 2008-09-05 7.2 HIGH N/A
tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.
CVE-2003-0573 1 Sgi 1 Irix 2008-09-05 5.0 MEDIUM N/A
The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.
CVE-2003-0599 1 Phpgroupware 1 Phpgroupware 2008-09-05 10.0 HIGH N/A
Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown implications, related to the VFS path being under the web document root.
CVE-2003-0433 1 Gnocatan-develop 1 Gnocatan 2008-09-05 7.5 HIGH N/A
Multiple buffer overflows in gnocatan 0.6.1 and earlier allow attackers to execute arbitrary code.
CVE-2003-0363 1 Licq 1 Licq 2008-09-05 7.5 HIGH N/A
Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.
CVE-2003-0366 1 Lysator 1 Lyskom-server 2008-09-05 5.0 MEDIUM N/A
lyskom-server 2.0.7 and earlier allows unauthenticated users to cause a denial of service (CPU consumption) via a large query.
CVE-2003-0361 1 Debian 1 Debian Linux 2008-09-05 7.5 HIGH N/A
gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.
CVE-2003-0194 1 Redhat 2 Linux, Tcpdump 2008-09-05 4.6 MEDIUM N/A
tcpdump does not properly drop privileges to the pcap user when starting up.
CVE-2003-0214 1 Debian 1 Mime-support 2008-09-05 4.6 MEDIUM N/A
run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2003-0061 1 Hp 1 Hp-ux 2008-09-05 7.2 HIGH N/A
Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.
CVE-2002-2370 1 Sws 1 Sws Simple Web Server 2008-09-05 5.0 MEDIUM N/A
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.
CVE-2003-0126 1 Multitech 1 Routefinder 550 Vpn 2008-09-05 7.5 HIGH N/A
The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.
CVE-2003-0155 1 Mozilla 1 Bonsai 2008-09-05 5.0 MEDIUM N/A
bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.
CVE-2002-2352 1 Neosoft 1 Neobook 2008-09-05 5.8 MEDIUM N/A
The NBActiveX.ocx ActiveX control in NeoBook 4 allows remote attackers to install and execute arbitrary programs.
CVE-2003-0241 1 Frontrange 1 Goldmine 2008-09-05 7.5 HIGH N/A
FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone.