CSV
180,962 results for "vulnerability" Page 52
CVE-2002-1399

Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2).

Jan 17, 2003 9 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.5
CVE-2002-2374

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

Dec 31, 2002 1 affected product(s) NVD
10.0
CVSS
1.2%
EPSS
⚡ 40.3
CVE-2003-0015

Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.

Feb 7, 2003 13 affected product(s) NVD
7.5
CVSS
23.9%
EPSS
⚡ 37.2
CVE-2002-0842

Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" response, which causes the format string specifiers to be returned from dav_lookup_uri() in mod_dav.c, which is then used in a call to ap_log_rerror().

Mar 3, 2003 1 affected product(s) NVD
7.5
CVSS
14.6%
EPSS
⚡ 34.4
CVE-2003-0002

Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.

Feb 7, 2003 2 affected product(s) NVD
6.8
CVSS
23.3%
EPSS
⚡ 34.2
CVE-2003-0059

Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.

Feb 19, 2003 2 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2002-1397

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.

Jan 17, 2003 8 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2003-0040

SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.

Feb 19, 2003 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2002-2383

SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names.

Dec 31, 2002 4 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2002-2391

SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.

Dec 31, 2002 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2003-0074

Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.

Feb 19, 2003 1 affected product(s) NVD
7.2
CVSS
1.2%
EPSS
⚡ 29.2
CVE-2002-1472

Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.

Mar 3, 2003 2 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2003-0027

Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.

Feb 7, 2003 10 affected product(s) NVD
5.0
CVSS
25.7%
EPSS
⚡ 27.7
CVE-2002-2399

Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Dec 31, 2002 1 affected product(s) NVD
6.4
CVSS
2.4%
EPSS
⚡ 26.3
CVE-2003-0076

Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.

Feb 19, 2003 4 affected product(s) NVD
6.4
CVSS
2.3%
EPSS
⚡ 26.3
CVE-2002-2416

Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
6.0%
EPSS
⚡ 21.8
CVE-2002-1405

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

Feb 19, 2003 9 affected product(s) NVD
5.0
CVSS
5.0%
EPSS
⚡ 21.5
CVE-2003-0073

Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.

Feb 19, 2003 8 affected product(s) NVD
5.0
CVSS
3.0%
EPSS
⚡ 20.9
CVE-2002-2403

Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
2.7%
EPSS
⚡ 20.8
CVE-2003-1079

Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.

Feb 18, 2003 9 affected product(s) NVD
5.0
CVSS
2.4%
EPSS
⚡ 20.7