Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2003-08-18 CVE-2003-0574 Unspecified vulnerability in SGI Irix
Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028.
local
low complexity
sgi
7.2
2003-08-18 CVE-2003-0573 Remote Security vulnerability in IRIX
The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.
network
low complexity
sgi
5.0
2003-08-18 CVE-2003-0572 Denial-Of-Service vulnerability in IRIX
Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).
network
low complexity
sgi
5.0
2003-08-18 CVE-2003-0567 Improper Input Validation vulnerability in Cisco products
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.
network
low complexity
cisco CWE-20
7.8
2003-08-18 CVE-2003-0561 Remote Security vulnerability in Iglooftp PRO 3.8
Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.
network
low complexity
iglooftp
7.5
2003-08-18 CVE-2003-0560 SQL Injection vulnerability in Virtual Programming Vp-Asp 5.0
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.
network
low complexity
virtual-programming
critical
10.0
2003-08-18 CVE-2003-0559 Remote Security vulnerability in PHPforum 2.0Rc1
mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.
network
low complexity
phpforum
7.5
2003-08-18 CVE-2003-0558 Remote Security vulnerability in Leapware Leapftp 2.7.3.600
Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.
network
low complexity
leapware
7.5
2003-08-18 CVE-2003-0557 Unspecified vulnerability in Lagarde Storefront
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.
network
low complexity
lagarde
7.5
2003-08-18 CVE-2003-0556 Unspecified vulnerability in Polycom Mgc-100, Mgc-25 and Mgc-50
Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demonstrated using the blast TCP stress tester.
network
low complexity
polycom
5.0