CVE-2003-0092
- EPSS 0.05%
- Published 02.04.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.
- EPSS 71.95%
- Published 02.04.2003 05:00:00
- Last modified 03.04.2025 01:03:51
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a s...
CVE-2003-1074
- EPSS 0.05%
- Published 28.03.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.
CVE-2003-0028
- EPSS 56.05%
- Published 25.03.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via ...
CVE-2003-1077
- EPSS 0.07%
- Published 05.03.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).
CVE-2003-0064
- EPSS 0.87%
- Published 03.03.2003 05:00:00
- Last modified 03.04.2025 01:03:51
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, wh...
CVE-2003-1078
- EPSS 0.6%
- Published 28.02.2003 05:00:00
- Last modified 03.04.2025 01:03:51
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.
- EPSS 19.34%
- Published 19.02.2003 05:00:00
- Last modified 03.04.2025 01:03:51
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.
- EPSS 1.11%
- Published 18.02.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be...
- EPSS 65.15%
- Published 07.02.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.