CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7326  CVE-2003-0499  Candidate  Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.  Assigned (20030630)  None (candidate not yet proposed)    View
7327  CVE-2003-0500  Candidate  SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.  Assigned (20030630)  None (candidate not yet proposed)    View
7328  CVE-2003-0501  Candidate  The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.  Assigned (20030702)  None (candidate not yet proposed)    View
7330  CVE-2003-0503  Candidate  Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.  Assigned (20030703)  None (candidate not yet proposed)    View
7331  CVE-2003-0504  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module.  Assigned (20030703)  None (candidate not yet proposed)    View

Page 715 of 20943, showing 5 records out of 104715 total, starting on record 3571, ending on 3575

Actions