Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2003-07-02 CVE-2003-0385 Local Security vulnerability in Linux 3.0.18/3.0.23
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.
local
low complexity
debian
7.2
2003-07-02 CVE-2003-0380 Unspecified vulnerability in Atftpd 0.6.0/0.6.1.1
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.
network
low complexity
atftpd
7.5
2003-06-30 CVE-2003-0414 Unspecified vulnerability in SUN ONE Application Server 7.0
The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.
local
low complexity
sun
7.2
2003-06-30 CVE-2003-0411 Improper Handling of Case Sensitivity vulnerability in Oracle SUN ONE Application Server 7.0
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.
network
low complexity
oracle CWE-178
7.5
2003-06-30 CVE-2003-0408 Buffer Overflow vulnerability in the Uptimes Project Upclient 5.0B7
Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.
local
low complexity
the-uptimes-project
7.2
2003-06-30 CVE-2003-0406 Unspecified vulnerability in Palmvnc 1.40
PalmVNC 1.40 and earlier stores passwords in plaintext in the PalmVNCDB, which is backed up to PCs that the Palm is synchronized with, which could allow attackers to gain privileges.
local
low complexity
palmvnc
7.2
2003-06-30 CVE-2003-0403 Denial Of Service vulnerability in Vignette Content Suite, Storyserver and Vignette
Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.
network
low complexity
vignette
7.5
2003-06-19 CVE-2003-1067 Local Security vulnerability in RETIRED: Oracle Solaris
Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.
local
low complexity
sun
7.2
2003-06-17 CVE-2003-1086 Remote Security vulnerability in Pmachine Free and Pmachine PRO
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.
network
low complexity
pmachine
7.5
2003-06-16 CVE-2003-0378 Unspecified vulnerability in Apple mac OS X
The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.
network
low complexity
apple
7.5