CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7336 | CVE-2003-0509 | Candidate | SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp. | Assigned (20030703) | None (candidate not yet proposed) | View | |
7337 | CVE-2003-0510 | Candidate | Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command. | Assigned (20030703) | None (candidate not yet proposed) | View | |
7328 | CVE-2003-0501 | Candidate | The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries. | Assigned (20030702) | None (candidate not yet proposed) | View | |
7323 | CVE-2003-0496 | Candidate | Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7324 | CVE-2003-0497 | Candidate | Cach・Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs. | Assigned (20030630) | None (candidate not yet proposed) | View |
Page 20229 of 20943, showing 5 records out of 104715 total, starting on record 101141, ending on 101145