Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2003-08-27 CVE-2003-0466 Off-by-one Error vulnerability in multiple products
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
network
low complexity
wuftpd redhat apple sun freebsd netbsd openbsd CWE-193
critical
9.8
2003-08-18 CVE-2003-0252 Off-by-one Error vulnerability in Linux-Nfs Nfs-Utils
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.
network
low complexity
linux-nfs CWE-193
critical
9.8
2003-06-09 CVE-2003-0356 Off-by-one Error vulnerability in Ethereal 0.8.13/0.9.11/0.9.3
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.
network
low complexity
ethereal CWE-193
critical
9.8
2003-05-12 CVE-2003-0174 Origin Validation Error vulnerability in SGI Irix
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.
network
low complexity
sgi CWE-346
critical
9.8
2003-04-22 CVE-2002-1484 Server-Side Request Forgery (SSRF) vulnerability in Siemens Db4Web 3.4/3.6
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.
network
low complexity
siemens CWE-918
critical
9.8
2002-12-31 CVE-2002-2119 Improper Handling of Case Sensitivity vulnerability in Novell Edirectory 8.6.2/8.7
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.
network
low complexity
novell CWE-178
critical
9.8
2002-12-31 CVE-2002-1820 Improper Handling of Case Sensitivity vulnerability in Ultimate PHP Board Project Ultimate PHP Board 1.0
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a."
network
low complexity
ultimate-php-board-project CWE-178
critical
9.8
2002-12-31 CVE-2002-1816 Off-by-one Error vulnerability in Redshift Atphttpd 0.4B
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
network
low complexity
redshift CWE-193
critical
9.8
2002-12-31 CVE-2002-1798 Forced Browsing vulnerability in Midicart PHP, Midicart PHP Maxi and Midicart PHP Plus
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.
network
low complexity
midicart CWE-425
critical
9.1
2002-12-18 CVE-2002-1347 Incorrect Calculation of Buffer Size vulnerability in multiple products
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.
network
low complexity
cyrusimap apple CWE-131
critical
9.8