National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

There are 136,302 matching records.
Displaying matches 129361 through 129380.
Vuln ID Summary CVSS Severity
CVE-2003-0279

Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 2.6 LOW
CVE-2003-0280

Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 10.0 HIGH
CVE-2003-0281

Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 4.6 MEDIUM
CVE-2003-0282

Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 2.6 LOW
CVE-2003-0283

Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 6.8 MEDIUM
CVE-2003-0284

Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 7.5 HIGH
CVE-2003-0285

IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2003-0286

SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 7.5 HIGH
CVE-2003-0287

Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 6.8 MEDIUM
CVE-2003-0288

Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 10.0 HIGH
CVE-2003-0289

Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 7.2 HIGH
CVE-2003-0290

Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2003-0291

3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2003-0292

Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka "Man-in-the-Middle" XSS.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 6.8 MEDIUM
CVE-2003-0293

PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2003-0294

autohtml.php in php-proxima 6.0 and earlier allows remote attackers to read arbitrary files via the name parameter in a modload operation.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 5.0 MEDIUM
CVE-2003-0295

Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 6.8 MEDIUM
CVE-2003-0296

The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 7.5 HIGH
CVE-2003-0297

c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 7.5 HIGH
CVE-2003-0298

The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large (1) literal and possibly (2) mailbox size values that cause either integer signedness errors or integer overflow errors.

Published: June 16, 2003; 12:00:00 AM -04:00
    V2: 7.5 HIGH