CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7330 | CVE-2003-0503 | Candidate | Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument. | Assigned (20030703) | None (candidate not yet proposed) | View | |
7329 | CVE-2003-0502 | Candidate | Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence followed by an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0421. | Assigned (20030611) | None (candidate not yet proposed) | View | |
7328 | CVE-2003-0501 | Candidate | The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries. | Assigned (20030702) | None (candidate not yet proposed) | View | |
7327 | CVE-2003-0500 | Candidate | SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7326 | CVE-2003-0499 | Candidate | Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations. | Assigned (20030630) | None (candidate not yet proposed) | View |
Page 19478 of 20943, showing 5 records out of 104715 total, starting on record 97386, ending on 97390