CSV
182,473 results for "vulnerability" Page 70
CVE-2003-1551

Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."

Dec 31, 2003 1 affected product(s) NVD
10.0
CVSS
1.6%
EPSS
⚡ 40.5
CVE-2003-1525

Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.

Dec 31, 2003 1 affected product(s) NVD
10.0
CVSS
1.4%
EPSS
⚡ 40.4
CVE-2003-1562

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.

Dec 31, 2003 45 affected product(s) NVD
7.6
CVSS
5.6%
EPSS
⚡ 32.1
CVE-2003-0978

Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.

Jan 5, 2004 6 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2003-0969

mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggering a format string vulnerability.

Jan 20, 2004 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2003-1022

Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory.

Jan 20, 2004 1 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2004-1785

SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.

Jan 3, 2004 6 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2003-1504

SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2003-1523

SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.

Dec 31, 2003 2 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2003-1530

SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2003-1532

SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2003-1533

SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.

Dec 31, 2003 1 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2003-0985

The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.

Jan 20, 2004 54 affected product(s) NVD
7.2
CVSS
1.2%
EPSS
⚡ 29.2
CVE-2003-1500

PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.8%
EPSS
⚡ 28
CVE-2003-1552

Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.1%
EPSS
⚡ 27.8
CVE-2003-1520

SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
1.1%
EPSS
⚡ 27.5
CVE-2003-1501

Directory traversal vulnerability in the file upload CGI of Gast Arbeiter 1.3 allows remote attackers to write arbitrary files via a .. (dot dot) in the req_file parameter.

Dec 31, 2003 1 affected product(s) NVD
6.4
CVSS
2.5%
EPSS
⚡ 26.3
CVE-2003-1545

Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.

Dec 31, 2003 2 affected product(s) NVD
5.0
CVSS
3.6%
EPSS
⚡ 21.1
CVE-2003-1529

Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.

Dec 31, 2003 1 affected product(s) NVD
5.0
CVSS
1.8%
EPSS
⚡ 20.6
CVE-2003-1542

Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.

Dec 31, 2003 1 affected product(s) NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.5