| OSVDB ID | Disclosure Date | Title |
|
8809
Description:
(Description Provided by CVE) : Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.
|
2003-03-11
|
SOHO Routefinder 550 HTTP GET Request Remote Overflow
|
|
10828
Description:
(Description Provided by CVE) : Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
|
2003-03-11
|
IBM Lotus Notes Server NotesRPC Authentication Long DN Overflow
|
|
13486
Description:
(Description Provided by CVE) : The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.
|
2003-03-11
|
SOHO Routefinder 550 Web Interface Default Admin Account
|
|
92823
Description:
HP Jetdirect 310x Print Server for Fast Ethernet contains an unspecified flaw that may allow a remote attacker to cause a denial of service or gain unauthorized access. No further details have been provided by the vendor.
|
2003-03-11
|
HP Jetdirect 310x Print Server for Fast Ethernet Unspecified Remote Issue
|
|
57015
Description:
Unknown / Incomplete
|
2003-03-10
|
DeleGate robot.txt User-Agent String Handling Remote Overflow
|
|
6196
Description:
(Description Provided by CVE) : Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.
|
2003-03-10
|
PeopleTools SchedulerTransfer Servlet Arbitrary File Overwrite
|
|
8930
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.
|
2003-03-10
|
Cross-Referencing Linux CGI v Parameter Traversal Arbitrary File Access
|
|
9794
Description:
A remote overflow exists in Qpopper. The server fails to properly check the length of macronames supplied to the pop_msg() function resulting in a buffer overflow. With a specially crafted request, an attacker can cause a denial of service or potentially execute arbitrary code. This attack requires valid user authentication credentials.
|
2003-03-10
|
Qpopper pop_msg() Macroname Remote Overflow
|
|
3371
Description:
Invision Power Board allows remote attackers to include arbitrary PHP files. The issue is due to poor sanity checking on arguments supplied to the ad_member.php script. By specifying an arbitrary path, a remote attacker can include a custom configuration file from a remote system, allowing them to execute arbitrary code and more.
|
2003-03-09
|
Invision Power Board ad_member.php Arbitrary File Include
|
|
5505
Description:
(Description Provided by CVE) : Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.
|
2003-03-09
|
PostNuke index.php theme Variable Arbitrary Command Execution
|
|
14475
Description:
(Description Provided by CVE) : Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
|
2003-03-09
|
Microsoft Windows Script Engine for Jscript JsArrayFunctionHeapSort Overflow
|
|
7982
Description:
PunBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate variables upon submission to certain administratively functions. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. No further details have been provided.
|
2003-03-08
|
PunBB Admin Function XSS
|
|
53382
Description:
Unknown / Incomplete
|
2003-03-08
|
Upload Lite upload.cgi Arbitrary File Upload
|
|
9909
Description:
(Description Provided by CVE) : MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
|
2003-03-08
|
MySQL datadir/my.cnf Modification Privilege Escalation
|
|
7356
Description:
Unknown / Incomplete
|
2003-03-07
|
MHonArc Malformed From: Address DoS
|
|
4465
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
2003-03-07
|
Ethereal NTLMSSP Dissector Overflow
|
|
4466
Description:
(Description Provided by CVE) : Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.
|
2003-03-07
|
Ethereal SOCKS Dissector Format String Overflow
|
|
8810
Description:
(Description Provided by CVE) : Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.
|
2003-03-07
|
MAILsweeper Missing MIME-Version Scan Bypass
|
|
58839
Description:
Unknown / Incomplete
|
2003-03-07
|
DBTools DBManager catalog.mdb Cleartext Local Credential Disclosure
|
|
28713
Description:
Unknown / Incomplete
|
2003-03-06
|
NetScreen High Machine Load Configuration Loss DoS
|
|
53880
Description:
PHP-Ping contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php not properly sanitizing user input supplied to the 'pingto' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2003-03-06
|
PHP-Ping index.php pingto Parameter Arbitrary Code Execution
|
|
35878
Description:
Unknown / Incomplete
|
2003-03-06
|
PHP-Nuke Members_List Module letter Parameter SQL Injection
|
|
35879
Description:
Unknown / Incomplete
|
2003-03-06
|
PHP-Nuke Your_Account Module Multiple Parameter SQL Injection
|
|
15147
Description:
(Description Provided by CVE) : Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.
|
2003-03-05
|
Solaris sendmail .forward Local Privilege Escalation
|
|
58904
Description:
Unknown / Incomplete
|
2003-03-05
|
Dr.Web Anti-virus File Name Handling Overflow
|
|
63186
Description:
Unknown / Incomplete
|
2003-03-05
|
Eudora Attachment Filename Handling Overflow DoS
|
|
54765
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.
|
2003-03-05
|
ONEdotOH Simple File Manager (SFM) File / Directory Name XSS
|
|
7549
Description:
(Description Provided by CVE) : Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
|
2003-03-05
|
lprold lpr Package lprm Command Line Overflow
|
|
8202
Description:
SAP server-side Remote Function Call (aka RFC) API contains a flaw that may allow a malicious user to undertake a brute-force attack against accounts without inducing a lock-out. The issue is due to insufficient checking placed on the Remote Function Call API which can be used in place of the GUI for authentication. It is possible that the flaw may allow account compromise, resulting in a loss of confidentiality.
|
2003-03-04
|
SAP R/3 46C/D Brute Force Logins Bypass Account Locking
|
|
7335
Description:
IlohaMail contains a variable injection flaw that may allow an attacker to gain elevated privileges. No further details have been provided.
|
2003-03-04
|
IlohaMail index.php session Parameter Arbitrary File Access
|
|
7400
Description:
IlohaMail contains a flaw that allows a remote attacker to access files outside of the web path. The issue is due to the index.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the int_lang variable. This flaw will lead to a loss of confidentiality.
|
2003-03-04
|
IlohaMail index.php init_lang Parameter Traversal Arbitrary File Access
|
|
91078
Description:
By default, phpWebSite installs with default admin credentials (username/password combination). The 'admin' account has a password of 'phpwebsite', which is publicly known and documented. This allows remote attackers to trivially access the program or system and gain privileged access.
|
2003-03-04
|
phpWebSite Default Admin Credentials
|
|
3950
Description:
The GNU Transport Layer Security Library contains a flaw that may allow a malicious user to disclose sensitive information about the information protected by the security features of the GNU Transport Layer Security Library. It is currently undocumented as to what exact conditions must be met to cause this condition. It is possible that the flaw may allow and attackers the ability to decrypted protected data resulting in a loss of information confidentiality.
|
2003-03-04
|
GNU TLS Library Information Leakage
|
|
4502
Description:
(Description Provided by CVE) : Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
|
2003-03-04
|
Sendmail headers.c crackaddr Function Address Field Handling Remote Overflow
|
|
6456
Description:
(Description Provided by CVE) : Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).
|
2003-03-04
|
file Command readelf.c tryelf() ELF Header Overflow
|
|
14743
Description:
(Description Provided by CVE) : Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact.
|
2003-03-04
|
AFCTR file Improper Memory Allocation
|
|
62224
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
|
2003-03-04
|
LoganPro User-Agent HTTP Header XSS
|
|
62225
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
|
2003-03-04
|
WebExpert User-Agent HTTP Header XSS
|
|
62226
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
|
2003-03-04
|
WebLogExpert Crafted Client Domain Name Inverse Lookup Log Corruption XSS
|
|
62227
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
|
2003-03-04
|
SurfStats Crafted Client Domain Name Inverse Lookup Log Corruption XSS
|