Vulnerabilities
Vulnerable Software
Linux:  >> Linux Kernel  >> 2.1.78  Security Vulnerabilities
Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.
CVSS Score
7.5
EPSS Score
0.068
Published
2003-12-31
Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.
CVSS Score
4.3
EPSS Score
0.003
Published
2003-12-31
Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.
CVSS Score
5.0
EPSS Score
0.002
Published
2003-12-31
Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.
CVSS Score
4.8
EPSS Score
0.001
Published
2003-12-31
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.
CVSS Score
5.0
EPSS Score
0.024
Published
2003-12-31
Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.
CVSS Score
5.0
EPSS Score
0.003
Published
2003-12-31
Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.
CVSS Score
5.0
EPSS Score
0.039
Published
2003-12-31
Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
CVSS Score
4.3
EPSS Score
0.006
Published
2003-12-31
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.
CVSS Score
7.2
EPSS Score
0.013
Published
2003-12-15
Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.
CVSS Score
5.0
EPSS Score
0.059
Published
2003-08-27


Contact Us

Shodan ® - All rights reserved