Weekly Vulnerabilities Reports > June 9 to 15, 2003
Overview
51 new vulnerabilities reported during this period, including 5 critical vulnerabilities and 22 high severity vulnerabilities. This weekly summary report vulnerabilities in 53 products from 33 vendors including Microsoft, Debian, Leszek Krupinski, Apple, and Redhat. Vulnerabilities are notably categorized as "Improper Restriction of Operations within the Bounds of a Memory Buffer", and "Classic Buffer Overflow".
- 42 reported vulnerabilities are remotely exploitables.
- 51 reported vulnerabilities are exploitable by an anonymous user.
- Microsoft has the most reported vulnerabilities, with 8 reported vulnerabilities.
- Microsoft has the most reported critical vulnerabilities, with 1 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
5 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2003-06-09 | CVE-2003-0356 | Ethereal Group | Unspecified vulnerability in Ethereal Group Ethereal Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions. | 10.0 |
2003-06-09 | CVE-2003-0331 | Ttcms | SQL-Injection vulnerability in Ttcms Ttforum 4 SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page. | 10.0 |
2003-06-09 | CVE-2003-0304 | Oneorzero | Remote Security vulnerability in Oneorzero Helpdesk 1.4Rc4 one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script. | 10.0 |
2003-06-09 | CVE-2003-0240 | Axis | Authentication Bypass vulnerability in Axis Network Camera HTTP The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash). | 10.0 |
2003-06-09 | CVE-2003-0224 | Microsoft | Unspecified vulnerability in Microsoft Internet Information Services 5.0 Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun." | 10.0 |
22 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2003-06-09 | CVE-2003-0332 | Working Resources INC | Security Bypass vulnerability in BadBlue The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension. | 7.6 |
2003-06-09 | CVE-2003-0361 | Debian | Remote Security vulnerability in Linux gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp. | 7.5 |
2003-06-09 | CVE-2003-0360 | Debian | Denial-Of-Service vulnerability in Linux Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code. | 7.5 |
2003-06-09 | CVE-2003-0357 | Ethereal Group | Integer Overflow vulnerability in Ethereal Mount Dissector Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors. | 7.5 |
2003-06-09 | CVE-2003-0328 | Epic | Unspecified vulnerability in Epic Epic4 Pre2.002/Pre2.003 EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation. | 7.5 |
2003-06-09 | CVE-2003-0324 | Epic | Buffer Overflow vulnerability in Epic Epic4 1.0.1 Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2) Statusbar capability. | 7.5 |
2003-06-09 | CVE-2003-0323 | Michael Sandrof | Unspecified vulnerability in Michael Sandrof Ircii 20020912 Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via responses that are not properly fed to the my_strcat function by (1) ctcp_buffer, (2) cannot_join_channel, (3) status_make_printable for Statusbar drawing, (4) create_server_list, and possibly other functions. | 7.5 |
2003-06-09 | CVE-2003-0321 | Colten Edwards | Remote Cluster() Heap Corruption vulnerability in BitchX Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled by the functions (1) send_ctcp, (2) cannot_join_channel, (3) cluster, (4) BX_compress_modes, (5) handle_oper_vision, and (6) ban_it. | 7.5 |
2003-06-09 | CVE-2003-0320 | Andy Prevost | Remote Security vulnerability in Ttcms header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script. | 7.5 |
2003-06-09 | CVE-2003-0319 | Smartmax Software | Remote Security vulnerability in MailMax Buffer overflow in the IMAP server (IMAPMax) for SmartMax MailMax 5.0.10.8 and earlier allows remote authenticated users to execute arbitrary code via a long SELECT command. | 7.5 |
2003-06-09 | CVE-2003-0309 | Microsoft | Unspecified vulnerability in Microsoft Internet Explorer 6.0.2800 Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability." | 7.5 |
2003-06-09 | CVE-2003-0307 | Poster | Remote Security vulnerability in Poster Version.Two Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field. | 7.5 |
2003-06-09 | CVE-2003-0242 | Apple | Unspecified vulnerability in Apple mac OS X IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies. | 7.5 |
2003-06-09 | CVE-2003-0241 | Frontrange | Unspecified vulnerability in Frontrange Goldmine 5.70/6.00 FrontRange GoldMine mail agent 5.70 and 6.00 before 30503 directly sends HTML to the default browser without setting its security zone or otherwise labeling it untrusted, which allows remote attackers to execute arbitrary code via a message that is rendered in IE using a less secure zone. | 7.5 |
2003-06-09 | CVE-2002-1463 | Symantec | Unspecified vulnerability in Symantec products Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections. | 7.5 |
2003-06-09 | CVE-2002-1461 | Webscriptworld | Remote Arbitrary Command Execution vulnerability in Webscriptworld web Shop Manager 1.1 Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box. | 7.5 |
2003-06-09 | CVE-2002-1459 | Leszek Krupinski | Unspecified vulnerability in Leszek Krupinski L-Forum 2.4.0 Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject. | 7.5 |
2003-06-09 | CVE-2002-1458 | Leszek Krupinski | Unspecified vulnerability in Leszek Krupinski L-Forum 2.4.0 Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body. | 7.5 |
2003-06-09 | CVE-2002-1457 | Leszek Krupinski | SQL Injection vulnerability in Leszek Krupinski L-Forum 2.4.0 SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter. | 7.5 |
2003-06-09 | CVE-2002-1456 | Khaled Mardam BEY | Buffer Overflow vulnerability in Khaled Mardam-Bey Mirc 6.0/6.0.1/6.0.2 Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value. | 7.5 |
2003-06-09 | CVE-2003-0306 | Microsoft | Local Security vulnerability in Windows XP Gold Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter. | 7.2 |
2003-06-09 | CVE-2003-0188 | LV Redhat | lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories. | 7.2 |
24 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2003-06-09 | CVE-2003-0223 | Microsoft | Unspecified vulnerability in Microsoft products Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message. | 6.8 |
2003-06-09 | CVE-2003-0362 | Debian | Denial-Of-Service vulnerability in Linux Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines. | 5.0 |
2003-06-09 | CVE-2003-0355 | Apple KDE | Remote Security vulnerability in Konqueror Embedded Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates. | 5.0 |
2003-06-09 | CVE-2003-0322 | Colten Edwards | Denial-Of-Service vulnerability in Bitchx Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash). | 5.0 |
2003-06-09 | CVE-2003-0305 | Cisco | Denial-Of-Service vulnerability in IOS The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967. | 5.0 |
2003-06-09 | CVE-2003-0303 | Oneorzero | SQL Injection vulnerability in Oneorzero Helpdesk 1.4Rc4 SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter. | 5.0 |
2003-06-09 | CVE-2003-0245 | Apache | Unspecified vulnerability in Apache Http Server Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors. | 5.0 |
2003-06-09 | CVE-2003-0227 | Microsoft | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Windows 2000 and Windows NT The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request. | 5.0 |
2003-06-09 | CVE-2003-0226 | Microsoft | Unspecified vulnerability in Microsoft Internet Information Services 5.0 Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled. | 5.0 |
2003-06-09 | CVE-2003-0225 | Microsoft | Unspecified vulnerability in Microsoft products The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page. | 5.0 |
2003-06-09 | CVE-2003-0189 | Apache | Unspecified vulnerability in Apache Http Server The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid usernames and passwords) when a threaded MPM is used. | 5.0 |
2003-06-09 | CVE-2002-1564 | Microsoft | Unspecified vulnerability in Microsoft Internet Explorer 5.01/5.5/6.0 Internet Explorer 5.5 and 6.0 allows remote attackers to steal potentially sensitive information from cookies via a cookie that contains script which is executed when a page is loaded, aka the "Script within Cookies Reading Cookies" vulnerability. | 5.0 |
2003-06-09 | CVE-2002-1462 | Organicphp | Authentication Bypassing vulnerability in OrganicPHP PHP-Affiliate Details.PHP Hidden Field details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields. | 5.0 |
2003-06-09 | CVE-2002-1460 | Leszek Krupinski | Unspecified vulnerability in Leszek Krupinski L-Forum 2.4.0 L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files. | 5.0 |
2003-06-09 | CVE-2002-1454 | Mywebserver | Unspecified vulnerability in Mywebserver 1.0.2 MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message. | 5.0 |
2003-06-13 | CVE-2003-0420 | Apple | Unspecified vulnerability in Apple mac OS X Server 10.2.6 Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool. | 4.6 |
2003-06-09 | CVE-2003-0358 | Falconseye Project Nethack Debian | Classic Buffer Overflow vulnerability in multiple products Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option. | 4.6 |
2003-06-09 | CVE-2003-0330 | Ambrosia Software | Local Security vulnerability in Maelstrom Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument. | 4.6 |
2003-06-09 | CVE-2003-0329 | Aclogic | Local Security vulnerability in Aclogic Cesarftp 0.99G CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges. | 4.6 |
2003-06-09 | CVE-2003-0326 | Slocate | Heap Overflow vulnerability in SLocate Path Malloc Integer Signing Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc. | 4.6 |
2003-06-09 | CVE-2003-0325 | Ambrosia Software | Unspecified vulnerability in Ambrosia Software Maelstrom 3.0.6 Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument. | 4.6 |
2003-06-09 | CVE-2003-0194 | Redhat | Unspecified vulnerability in Redhat Linux and Tcpdump tcpdump does not properly drop privileges to the pcap user when starting up. | 4.6 |
2003-06-09 | CVE-2003-0318 | Francisco Burzi | Cross-Site Scripting vulnerability in PHP-Nuke Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter. | 4.3 |
2003-06-09 | CVE-2002-1455 | Omnicron | Cross-Site Scripting vulnerability in OmniHTTPD Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe. | 4.3 |
0 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|