Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2003-1416 | 1 Bisonftp | 1 Bisonftp Server 4 | 2017-07-29 | 4.3 MEDIUM | N/A |
BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command. | |||||
CVE-2006-7171 | 1 Koan Software | 1 Mega Mall | 2017-07-29 | 5.0 MEDIUM | N/A |
product_review.php in Koan Software Mega Mall allows remote attackers to obtain the installation path via a request with an empty value of the x[] parameter. | |||||
CVE-2006-6581 | 1 Vernet Loic | 1 Php Debug | 2017-07-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter. | |||||
CVE-2003-1444 | 1 Kaspersky Lab | 1 Kaspersky Anti-virus | 2017-07-29 | 4.4 MEDIUM | N/A |
Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname. | |||||
CVE-2003-1402 | 1 Kietu | 1 Kietu | 2017-07-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015. | |||||
CVE-2002-2237 | 1 Tftp | 1 Tftp Server | 2017-07-29 | 5.0 MEDIUM | N/A |
tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux. | |||||
CVE-2006-6241 | 1 Telnet Ftp Server | 1 Telnet Ftp Server | 2017-07-29 | 4.0 MEDIUM | N/A |
Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to cause a denial of service (crash) via consecutive RETR commands. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2003-1419 | 1 Netscape | 1 Navigator | 2017-07-29 | 4.3 MEDIUM | N/A |
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function. | |||||
CVE-2002-2239 | 1 Cisco | 3 Catalyst 6500, Catalyst 7600, Ios | 2017-07-29 | 7.8 HIGH | N/A |
The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet. | |||||
CVE-2003-1488 | 1 Truelogik | 1 Truegalerie | 2017-07-29 | 6.4 MEDIUM | N/A |
The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1. | |||||
CVE-2003-1365 | 1 Perl | 1 Cgi Lite | 2017-07-29 | 5.0 MEDIUM | N/A |
The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs. | |||||
CVE-2001-1584 | 1 Michael Barretto | 1 Cardboard | 2017-07-29 | 7.5 HIGH | N/A |
CardBoard 2.4 greeting card CGI by Michael Barretto allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient field. | |||||
CVE-2003-1471 | 1 Alt-n | 1 Mdaemon | 2017-07-29 | 6.3 MEDIUM | N/A |
MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number. | |||||
CVE-2003-1450 | 1 Bitchx | 1 Bitchx | 2017-07-29 | 5.0 MEDIUM | N/A |
BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message. | |||||
CVE-2003-1403 | 1 Dotbr | 1 Botbr | 2017-07-29 | 7.5 HIGH | N/A |
foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | |||||
CVE-2003-1443 | 1 Kaspersky Lab | 1 Kaspersky Anti-virus | 2017-07-29 | 4.4 MEDIUM | N/A |
Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com. | |||||
CVE-2007-0102 | 1 Apple | 1 Preview | 2017-07-29 | 6.8 MEDIUM | N/A |
The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node. | |||||
CVE-2003-1425 | 1 Cpanel | 1 Cpanel | 2017-07-29 | 10.0 HIGH | N/A |
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. | |||||
CVE-2003-1350 | 1 List Site Pro | 1 List Site Pro | 2017-07-29 | 4.3 MEDIUM | N/A |
List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field. | |||||
CVE-2003-1441 | 1 Posadis | 1 Posadis | 2017-07-29 | 4.3 MEDIUM | N/A |
Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference. |