NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
74376  CVE-2003-1306  Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.    2.6  Low  2017-01-03  2008-09-05  View
74377  CVE-2003-1307  ** DISPUTED ** The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server"s process group and use the server"s file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server"s TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."    4.3  Medium  2017-01-03  2008-09-05  View
74378  CVE-2003-1308  CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.    4.6  Medium  2017-01-03  2008-09-05  View
74379  CVE-2003-1309  The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack").    10  High  2017-01-03  2008-09-05  View
74380  CVE-2003-1310  The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").    4.6  Medium  2017-01-03  2008-09-05  View

Page 1590 of 17672, showing 5 records out of 88360 total, starting on record 7946, ending on 7950

Actions