CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7765  CVE-2003-0941  Candidate  web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.  Assigned (20031111)  None (candidate not yet proposed)    View
7764  CVE-2003-0940  Candidate  Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.  Assigned (20031111)  None (candidate not yet proposed)    View
7763  CVE-2003-0939  Candidate  eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code via a connect packet with a 256 byte segment to the niserver (aka serv.exe) process on TCP port 7269, which prevents the server from NULL terminating the string and leads to a buffer overflow.  Assigned (20031111)  None (candidate not yet proposed)    View
7762  CVE-2003-0938  Candidate  vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which is found and loaded by SAP DB before the real DLL, as demonstrated using the SQLAT stored procedure.  Assigned (20031111)  None (candidate not yet proposed)    View
7761  CVE-2003-0937  Candidate  SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.  Assigned (20031111)  None (candidate not yet proposed)    View

Page 19391 of 20943, showing 5 records out of 104715 total, starting on record 96951, ending on 96955

Actions