Total
275044 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2003-1179 | 1 Advanced Poll | 1 Advanced Poll | 2024-11-20 | N/A |
Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php. | ||||
CVE-2003-1178 | 1 Advanced Poll | 1 Advanced Poll | 2024-11-20 | N/A |
Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter. | ||||
CVE-2003-1177 | 1 Atrium Software | 1 Mercur Mailserver | 2024-11-20 | N/A |
Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server. | ||||
CVE-2003-1176 | 1 Bdc Enterprises | 1 Web Wiz Forums | 2024-11-20 | N/A |
post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter. | ||||
CVE-2003-1175 | 1 Synthetic Reality | 1 Sympoll | 2024-11-20 | N/A |
Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter. | ||||
CVE-2003-1174 | 1 Nullsoft | 1 Shoutcast Server | 2024-11-20 | N/A |
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL. | ||||
CVE-2003-1173 | 1 Centrinity | 1 Centrinity Firstclass | 2024-11-20 | N/A |
Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory. | ||||
CVE-2003-1172 | 1 Apache | 1 Cocoon | 2024-11-20 | N/A |
Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter. | ||||
CVE-2003-1171 | 1 Mod Security | 1 Mod Security | 2024-11-20 | N/A |
Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data. | ||||
CVE-2003-1170 | 1 Gernot Stocker | 1 Kpopup | 2024-11-20 | N/A |
Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments. | ||||
CVE-2003-1169 | 1 Datev | 1 Nutzungskontrolle | 2024-11-20 | N/A |
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle. | ||||
CVE-2003-1168 | 1 Http Commander | 1 Http Commander | 2024-11-20 | N/A |
HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message. | ||||
CVE-2003-1167 | 1 Gernot Stocker | 1 Kpopup | 2024-11-20 | N/A |
misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program. | ||||
CVE-2003-1166 | 1 Http Commander | 1 Http Commander | 2024-11-20 | N/A |
Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter. | ||||
CVE-2003-1165 | 1 Brs | 1 Webweaver | 2024-11-20 | N/A |
Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header. | ||||
CVE-2003-1164 | 1 Mldonkey | 1 Mldonkey | 2024-11-20 | N/A |
Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page. | ||||
CVE-2003-1163 | 1 Ganglia | 1 Gmond | 2024-11-20 | N/A |
hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index. | ||||
CVE-2003-1162 | 1 Tritanium Scripts | 1 Tritanium Bulletin Board | 2024-11-20 | N/A |
index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters. | ||||
CVE-2003-1161 | 1 Linux | 1 Linux Kernel | 2024-11-20 | N/A |
exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function. | ||||
CVE-2003-1160 | 1 Seyeon | 1 Flexwatch Network Video Server | 2024-11-20 | N/A |
FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//). |