CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7313  CVE-2003-0486  Candidate  SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.  Assigned (20030627)  None (candidate not yet proposed)    View
7314  CVE-2003-0487  Candidate  Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module.  Assigned (20030627)  None (candidate not yet proposed)    View
7315  CVE-2003-0488  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.  Assigned (20030627)  None (candidate not yet proposed)    View
7316  CVE-2003-0489  Candidate  tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.  Assigned (20030627)  None (candidate not yet proposed)    View
7317  CVE-2003-0490  Candidate  The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code.  Assigned (20030627)  None (candidate not yet proposed)    View

Page 20233 of 20943, showing 5 records out of 104715 total, starting on record 101161, ending on 101165

Actions