CSV
180,962 results for "vulnerability" Page 54
CVE-2003-0161

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

Apr 2, 2003 111 affected product(s) NVD
10.0
CVSS
38.2%
EPSS
⚡ 51.5
CVE-2002-0690

Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.

Apr 11, 2003 1 affected product(s) NVD
10.0
CVSS
8.4%
EPSS
⚡ 42.5
CVE-2003-0098

Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.

Mar 3, 2003 4 affected product(s) NVD
10.0
CVSS
5.2%
EPSS
⚡ 41.6
CVE-2002-1519

Format string vulnerability in the CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the password parameter.

Apr 2, 2003 9 affected product(s) NVD
10.0
CVSS
4.3%
EPSS
⚡ 41.3
CVE-2003-0028

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

Mar 25, 2003 165 affected product(s) NVD
7.5
CVSS
15.0%
EPSS
⚡ 34.5
CVE-2003-0009

Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.

Mar 7, 2003 3 affected product(s) NVD
6.8
CVSS
16.5%
EPSS
⚡ 32.1
CVE-2003-0081

Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.

Mar 18, 2003 11 affected product(s) NVD
7.5
CVSS
5.8%
EPSS
⚡ 31.7
CVE-2003-0167

Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.

Apr 2, 2003 9 affected product(s) NVD
7.5
CVSS
2.5%
EPSS
⚡ 30.8
CVE-2002-1505

SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.

Apr 2, 2003 4 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2003-0152

Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.

Apr 2, 2003 1 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2002-1408

Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name.

Apr 11, 2003 2 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2003-0097

Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).

Mar 3, 2003 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2002-1406

Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."

Apr 11, 2003 1 affected product(s) NVD
7.2
CVSS
0.6%
EPSS
⚡ 29
CVE-2003-1074

Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.

Mar 28, 2003 2 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2002-1548

Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."

Mar 31, 2003 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2002-1544

Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get.

Mar 31, 2003 1 affected product(s) NVD
6.4
CVSS
1.6%
EPSS
⚡ 26.1
CVE-2003-0083

Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.

Apr 2, 2003 2 affected product(s) NVD
5.0
CVSS
17.4%
EPSS
⚡ 25.2
CVE-2003-0011

Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.

Mar 24, 2003 2 affected product(s) NVD
5.0
CVSS
13.3%
EPSS
⚡ 24
CVE-2002-1533

Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).

Mar 31, 2003 1 affected product(s) NVD
5.8
CVSS
2.4%
EPSS
⚡ 23.9
CVE-2002-1559

Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.

Mar 31, 2003 1 affected product(s) NVD
5.0
CVSS
9.2%
EPSS
⚡ 22.8