CSV
181,585 results for "vulnerability" Page 65
CVE-2003-0886

Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.

Dec 1, 2003 7 affected product(s) NVD
10.0
CVSS
12.1%
EPSS
⚡ 43.6
CVE-2003-1240

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
6.9%
EPSS
⚡ 32.1
CVE-2003-1227

PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.

Dec 31, 2003 2 affected product(s) NVD
7.5
CVSS
6.7%
EPSS
⚡ 32
CVE-2003-1092

Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact.

Dec 31, 2003 10 affected product(s) NVD
7.5
CVSS
3.7%
EPSS
⚡ 31.1
CVE-2003-1131

PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.

Dec 31, 2003 4 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2003-0946

Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address argument of a "MAIL FROM" command.

Dec 15, 2003 2 affected product(s) NVD
7.5
CVSS
3.1%
EPSS
⚡ 30.9
CVE-2003-1178

Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.

Dec 31, 2003 3 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2003-1103

SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands.

Dec 31, 2003 2 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2003-1180

Directory traversal vulnerability in Advanced Poll 2.0.2 allows remote attackers to read arbitrary files or inject arbitrary local PHP files via .. sequences in the base_path or pollvars[lang] parameters to the admin files (1) index.php, (2) admin_tpl_new.php, (3) admin_tpl_misc_new.php, (4) admin_templates_misc.php, (5) admin_templates.php, (6) admin_stats.php, (7) admin_settings.php, (8) admin_preview.php, (9) admin_password.php, (10) admin_logout.php, (11) admin_license.php, (12) admin_help.php, (13) admin_embed.php, (14) admin_edit.php, or (15) admin_comment.php.

Dec 31, 2003 3 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2003-0824

Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.

Dec 15, 2003 8 affected product(s) NVD
5.0
CVSS
34.6%
EPSS
⚡ 30.4
CVE-2003-0363

Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.

Dec 31, 2003 2 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2003-1098

The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.

Dec 31, 2003 1 affected product(s) NVD
7.2
CVSS
1.3%
EPSS
⚡ 29.2
CVE-2003-1172

Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.

Dec 31, 2003 3 affected product(s) NVD
5.0
CVSS
30.8%
EPSS
⚡ 29.2
CVE-2003-1170

Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments.

Dec 31, 2003 2 affected product(s) NVD
7.2
CVSS
0.6%
EPSS
⚡ 29
CVE-2003-1057

Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.

Dec 8, 2003 8 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2003-1076

Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.

Dec 31, 2003 6 affected product(s) NVD
7.2
CVSS
0.3%
EPSS
⚡ 28.9
CVE-2003-1082

Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.

Dec 31, 2003 7 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2003-1175

Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8
CVE-2003-1211

Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter.

Dec 31, 2003 NVD
6.8
CVSS
1.5%
EPSS
⚡ 27.6
CVE-2003-1238

Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of the (1) Team, (2) News, and (3) Liens modules.

Dec 31, 2003 4 affected product(s) NVD
5.8
CVSS
2.1%
EPSS
⚡ 23.8