NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
73736 | CVE-2003-0620 | Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable. | 2 | 4.6 | Medium | 2017-01-03 | 2016-10-17 | View | |
73737 | CVE-2003-0621 | The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
73738 | CVE-2003-0622 | The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
73739 | CVE-2003-0623 | Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
73740 | CVE-2003-0624 | Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 1462 of 17672, showing 5 records out of 88360 total, starting on record 7306, ending on 7310