CSV
181,012 results for "vulnerability" Page 55
CVE-2003-0161

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

Apr 2, 2003 111 affected product(s) NVD
10.0
CVSS
38.2%
EPSS
⚡ 51.5
CVE-2003-0196

Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.

May 5, 2003 77 affected product(s) NVD
10.0
CVSS
22.8%
EPSS
⚡ 46.8
CVE-2002-0690

Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.

Apr 11, 2003 1 affected product(s) NVD
10.0
CVSS
8.4%
EPSS
⚡ 42.5
CVE-2002-1519

Format string vulnerability in the CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the password parameter.

Apr 2, 2003 9 affected product(s) NVD
10.0
CVSS
4.3%
EPSS
⚡ 41.3
CVE-2002-1482

SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.

Apr 22, 2003 3 affected product(s) NVD
10.0
CVSS
3.7%
EPSS
⚡ 41.1
CVE-2003-0167

Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.

Apr 2, 2003 9 affected product(s) NVD
7.5
CVSS
2.5%
EPSS
⚡ 30.8
CVE-2002-1505

SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.

Apr 2, 2003 4 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2003-0152

Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.

Apr 2, 2003 1 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2002-1408

Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name.

Apr 11, 2003 2 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2002-1465

SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

Apr 22, 2003 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2002-1406

Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."

Apr 11, 2003 1 affected product(s) NVD
7.2
CVSS
0.6%
EPSS
⚡ 29
CVE-2002-1480

Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.

Apr 22, 2003 1 affected product(s) NVD
6.8
CVSS
4.3%
EPSS
⚡ 28.5
CVE-2003-1146

Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

May 11, 2003 1 affected product(s) NVD
6.8
CVSS
3.5%
EPSS
⚡ 28.2
CVE-2002-1464

Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

Apr 22, 2003 1 affected product(s) NVD
6.8
CVSS
1.5%
EPSS
⚡ 27.7
CVE-2002-1425

Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.

Apr 11, 2003 1 affected product(s) NVD
6.4
CVSS
1.9%
EPSS
⚡ 26.2
CVE-2003-0083

Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.

Apr 2, 2003 2 affected product(s) NVD
5.0
CVSS
17.4%
EPSS
⚡ 25.2
CVE-2002-1437

Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.

Apr 11, 2003 4 affected product(s) NVD
5.0
CVSS
17.0%
EPSS
⚡ 25.1
CVE-2002-1417

Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot), which is mapped to the directory separator.

Apr 11, 2003 4 affected product(s) NVD
5.0
CVSS
16.6%
EPSS
⚡ 25
CVE-2002-1525

Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.

Apr 2, 2003 2 affected product(s) NVD
5.0
CVSS
8.1%
EPSS
⚡ 22.4
CVE-2002-1429

Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter.

Apr 11, 2003 1 affected product(s) NVD
5.0
CVSS
6.6%
EPSS
⚡ 22