CSV
182,475 results for "vulnerability" Page 72
CVE-2003-1027

Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."

Jan 20, 2004 10 affected product(s) NVD
10.0
CVSS
38.1%
EPSS
⚡ 51.4
CVE-2003-1026

Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."

Jan 20, 2004 10 affected product(s) NVD
9.3
CVSS
39.2%
EPSS
⚡ 49
CVE-2003-0816

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.

Feb 3, 2004 9 affected product(s) NVD
7.5
CVSS
48.4%
EPSS
⚡ 44.5
CVE-2004-0030 CRITICAL

PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

Jan 20, 2004 1 affected product(s) NVD
9.8
CVSS
7.3%
EPSS
⚡ 41.4
CVE-2004-1244

Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

Feb 8, 2004 1 affected product(s) NVD
7.5
CVSS
33.2%
EPSS
⚡ 40
CVE-2003-0814

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.

Feb 3, 2004 9 affected product(s) NVD
7.5
CVSS
27.7%
EPSS
⚡ 38.3
CVE-2003-0823

Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.

Feb 3, 2004 9 affected product(s) NVD
7.5
CVSS
26.0%
EPSS
⚡ 37.8
CVE-2003-0815

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.

Feb 3, 2004 9 affected product(s) NVD
7.5
CVSS
18.7%
EPSS
⚡ 35.6
CVE-2004-0069

Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.

Feb 17, 2004 1 affected product(s) NVD
7.5
CVSS
9.8%
EPSS
⚡ 32.9
CVE-2004-0073

PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that contains a malicious serverdata.php script.

Feb 17, 2004 1 affected product(s) NVD
7.5
CVSS
8.8%
EPSS
⚡ 32.6
CVE-2003-0989

tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.

Feb 17, 2004 2 affected product(s) NVD
7.5
CVSS
5.3%
EPSS
⚡ 31.6
CVE-2004-0070

PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.

Feb 17, 2004 1 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2003-0902

Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.

Feb 3, 2004 2 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2003-0700

The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.

Feb 17, 2004 1 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2004-2087

Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.

Feb 8, 2004 1 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2003-1214

Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.

Feb 11, 2004 12 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2004-0068

PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.

Feb 17, 2004 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2004-0035

SQL injection vulnerability in register.php for Phorum 3.4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the hide_email parameter.

Jan 20, 2004 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2003-1024

Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.

Jan 20, 2004 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2004-0001

Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.

Feb 17, 2004 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9