CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7326 | CVE-2003-0499 | Candidate | Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7327 | CVE-2003-0500 | Candidate | SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name. | Assigned (20030630) | None (candidate not yet proposed) | View | |
7328 | CVE-2003-0501 | Candidate | The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries. | Assigned (20030702) | None (candidate not yet proposed) | View | |
7330 | CVE-2003-0503 | Candidate | Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument. | Assigned (20030703) | None (candidate not yet proposed) | View | |
7331 | CVE-2003-0504 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module. | Assigned (20030703) | None (candidate not yet proposed) | View |
Page 715 of 20943, showing 5 records out of 104715 total, starting on record 3571, ending on 3575