CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7313 | CVE-2003-0486 | Candidate | SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7314 | CVE-2003-0487 | Candidate | Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7315 | CVE-2003-0488 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7316 | CVE-2003-0489 | Candidate | tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute. | Assigned (20030627) | None (candidate not yet proposed) | View | |
7317 | CVE-2003-0490 | Candidate | The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code. | Assigned (20030627) | None (candidate not yet proposed) | View |
Page 20233 of 20943, showing 5 records out of 104715 total, starting on record 101161, ending on 101165