Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown
CVE-2004-0594
Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete.
0
Attacker Value
Unknown
CVE-2004-1997
Disclosure Date: May 05, 2004 (last updated February 22, 2025)
Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2003-0615
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.
0
Attacker Value
Unknown
CVE-2003-0190
Disclosure Date: May 12, 2003 (last updated February 22, 2025)
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
0
Attacker Value
Unknown
CVE-2003-0147
Disclosure Date: March 31, 2003 (last updated February 22, 2025)
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).
0
Attacker Value
Unknown
CVE-2002-0985
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.
0
Attacker Value
Unknown
CVE-2002-0083
Disclosure Date: March 15, 2002 (last updated February 22, 2025)
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
0