NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
74350  CVE-2003-1280  Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.    Medium  2017-01-03  2008-09-05  View
74349  CVE-2003-1279  S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6) /tmp/sgml2html$$tmp /tmp/sgml2html$$tmp1 /tmp/sgml2html$$tmp2 by sglm2html.    4.6  Medium  2017-01-03  2008-09-05  View
74348  CVE-2003-1278  Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.    4.3  Medium  2017-01-03  2008-09-05  View
74347  CVE-2003-1277  Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html    4.3  Medium  2017-01-03  2008-09-05  View
74346  CVE-2003-1276  Netfone.exe of NetTelephone 3.5.6 uses weak encryption for user PIN"s and stores user account numbers in plaintext in the HKEY_CURRENT_USERSoftwareMediaRing.comSDKNetTelephonesettings registry key, which could allow local users to gain unauthorized access to NetTelephone accounts.    4.6  Medium  2017-01-03  2008-09-05  View

Page 16089 of 17672, showing 5 records out of 88360 total, starting on record 80441, ending on 80445

Actions