CSV
181,286 results for "vulnerability" Page 58
CVE-2003-0309

Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."

Jun 9, 2003 1 affected product(s) NVD
7.5
CVSS
50.0%
EPSS
⚡ 45
CVE-2003-0478

Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.

Aug 7, 2003 5 affected product(s) NVD
10.0
CVSS
12.3%
EPSS
⚡ 43.7
CVE-2003-0473

Unknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.

Aug 7, 2003 1 affected product(s) NVD
10.0
CVSS
2.3%
EPSS
⚡ 40.7
CVE-2003-0331

SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.

Jun 9, 2003 1 affected product(s) NVD
10.0
CVSS
1.9%
EPSS
⚡ 40.6
CVE-2003-0391

Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.

Jul 2, 2003 1 affected product(s) NVD
7.5
CVSS
3.5%
EPSS
⚡ 31.1
CVE-2003-0286

SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.

Jun 16, 2003 1 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2003-0377

SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.

Jun 16, 2003 1 affected product(s) NVD
7.5
CVSS
2.5%
EPSS
⚡ 30.7
CVE-2003-1086

PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.

Jun 17, 2003 3 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.7
CVE-2003-0354

Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.

Jun 16, 2003 5 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2003-0413

Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.

Jun 30, 2003 1 affected product(s) NVD
6.8
CVSS
6.7%
EPSS
⚡ 29.2
CVE-2003-0289

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

Jun 16, 2003 2 affected product(s) NVD
7.2
CVSS
1.1%
EPSS
⚡ 29.1
CVE-2003-0489

tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.

Aug 7, 2003 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2003-0416

Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.

Jun 30, 2003 1 affected product(s) NVD
6.8
CVSS
4.3%
EPSS
⚡ 28.5
CVE-2003-0278

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

Jun 16, 2003 2 affected product(s) NVD
6.8
CVSS
3.9%
EPSS
⚡ 28.4
CVE-2003-0283

Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

Jun 16, 2003 1 affected product(s) NVD
6.8
CVSS
4.0%
EPSS
⚡ 28.4
CVE-2003-0310

Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

Jun 16, 2003 1 affected product(s) NVD
6.8
CVSS
3.2%
EPSS
⚡ 28.2
CVE-2003-0312

Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.

Jun 16, 2003 1 affected product(s) NVD
6.4
CVSS
7.4%
EPSS
⚡ 27.8
CVE-2003-0292

Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka "Man-in-the-Middle" XSS.

Jun 16, 2003 1 affected product(s) NVD
6.8
CVSS
1.6%
EPSS
⚡ 27.7
CVE-2003-0295

Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.

Jun 16, 2003 1 affected product(s) NVD
6.8
CVSS
1.6%
EPSS
⚡ 27.7
CVE-2003-0217

Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.

Jun 16, 2003 1 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6