CSV
181,474 results for "vulnerability" Page 62
CVE-2003-0528

Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.

Sep 17, 2003 48 affected product(s) NVD
10.0
CVSS
41.0%
EPSS
⚡ 52.3
CVE-2003-0715

Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.

Sep 17, 2003 48 affected product(s) NVD
10.0
CVSS
40.3%
EPSS
⚡ 52.1
CVE-2003-0693

A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.

Sep 22, 2003 1 affected product(s) NVD
10.0
CVSS
11.4%
EPSS
⚡ 43.4
CVE-2003-0734

Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the system.

Oct 20, 2003 1 affected product(s) NVD
10.0
CVSS
2.3%
EPSS
⚡ 40.7
CVE-2003-0784

Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.

Oct 6, 2003 3 affected product(s) NVD
10.0
CVSS
2.1%
EPSS
⚡ 40.6
CVE-2002-1567

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

Oct 6, 2003 1 affected product(s) NVD
6.8
CVSS
27.1%
EPSS
⚡ 35.3
CVE-2003-0695

Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.

Oct 6, 2003 1 affected product(s) NVD
7.5
CVSS
3.9%
EPSS
⚡ 31.2
CVE-2003-0672

Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.

Aug 27, 2003 2 affected product(s) NVD
7.5
CVSS
3.1%
EPSS
⚡ 30.9
CVE-2003-0699

The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.

Aug 27, 2003 2 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2003-0708

Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.

Oct 20, 2003 1 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2003-0735

SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.

Oct 20, 2003 1 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2003-0779

SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.

Sep 22, 2003 7 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2003-0680

Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.

Oct 6, 2003 3 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2003-0751

SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.

Oct 20, 2003 3 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2003-0752

SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.

Oct 20, 2003 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2003-0871

Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."

Nov 3, 2003 2 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2003-0671

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.

Aug 27, 2003 4 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 29
CVE-2003-0697

Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.

Oct 6, 2003 3 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2003-1197

Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.

Oct 30, 2003 NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2003-1187

Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.

Nov 2, 2003 2 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5