CSV
182,473 results for "vulnerability" Page 71
CVE-2003-1027

Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."

Jan 20, 2004 10 affected product(s) NVD
10.0
CVSS
38.1%
EPSS
⚡ 51.4
CVE-2003-1026

Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."

Jan 20, 2004 10 affected product(s) NVD
9.3
CVSS
39.2%
EPSS
⚡ 49
CVE-2003-0816

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.

Feb 3, 2004 9 affected product(s) NVD
7.5
CVSS
48.4%
EPSS
⚡ 44.5
CVE-2004-0030 CRITICAL

PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

Jan 20, 2004 1 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2003-1551

Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."

Dec 31, 2003 1 affected product(s) NVD
10.0
CVSS
1.6%
EPSS
⚡ 40.5
CVE-2004-1244

Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

Feb 8, 2004 1 affected product(s) NVD
7.5
CVSS
33.2%
EPSS
⚡ 40
CVE-2003-0814

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.

Feb 3, 2004 9 affected product(s) NVD
7.5
CVSS
27.7%
EPSS
⚡ 38.3
CVE-2003-0823

Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.

Feb 3, 2004 9 affected product(s) NVD
7.5
CVSS
26.0%
EPSS
⚡ 37.8
CVE-2003-0815

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.

Feb 3, 2004 9 affected product(s) NVD
7.5
CVSS
18.7%
EPSS
⚡ 35.6
CVE-2003-1562

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.

Dec 31, 2003 45 affected product(s) NVD
7.6
CVSS
5.6%
EPSS
⚡ 32.1
CVE-2003-0978

Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.

Jan 5, 2004 6 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2003-0969

mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggering a format string vulnerability.

Jan 20, 2004 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2003-0902

Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.

Feb 3, 2004 2 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2003-1022

Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory.

Jan 20, 2004 1 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2004-2087

Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.

Feb 8, 2004 1 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2004-1785

SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.

Jan 3, 2004 6 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2004-0035

SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.

Jan 20, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2003-0985

The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.

Jan 20, 2004 54 affected product(s) NVD
7.2
CVSS
1.2%
EPSS
⚡ 29.2
CVE-2003-1024

Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.

Jan 20, 2004 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2003-1552

Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.

Dec 31, 2003 1 affected product(s) NVD
6.8
CVSS
2.1%
EPSS
⚡ 27.8