CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7316  CVE-2003-0489  Candidate  tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.  Assigned (20030627)  None (candidate not yet proposed)    View
7317  CVE-2003-0490  Candidate  The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs with malicious code.  Assigned (20030627)  None (candidate not yet proposed)    View
7318  CVE-2003-0491  Candidate  The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.  Assigned (20030627)  None (candidate not yet proposed)    View
7319  CVE-2003-0492  Candidate  Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.  Assigned (20030627)  None (candidate not yet proposed)    View
7320  CVE-2003-0493  Candidate  Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.  Assigned (20030627)  None (candidate not yet proposed)    View

Page 713 of 20943, showing 5 records out of 104715 total, starting on record 3561, ending on 3565

Actions