Latest CVE Feed
-
7.5
HIGHCVE-2003-0772
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.... Read more
- EPSS Score: %83.20
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0774
saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.... Read more
- EPSS Score: %1.50
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0776
saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.... Read more
- EPSS Score: %0.74
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0768
Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.... Read more
Affected Products : asp.net- EPSS Score: %17.17
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0771
Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.... Read more
Affected Products : apache_gallery- EPSS Score: %0.09
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0779
SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.... Read more
Affected Products : asterisk- EPSS Score: %0.03
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0775
saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).... Read more
- EPSS Score: %1.58
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0778
saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).... Read more
- EPSS Score: %0.83
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0722
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.... Read more
Affected Products : solaris- EPSS Score: %89.40
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0773
saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.... Read more
- EPSS Score: %1.27
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2003-0780
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.... Read more
- EPSS Score: %70.05
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0769
Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.... Read more
Affected Products : icq- EPSS Score: %0.69
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0777
saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).... Read more
- EPSS Score: %0.83
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0693
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-200... Read more
Affected Products : openssh- EPSS Score: %32.68
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0762
Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).... Read more
Affected Products : foxweb- EPSS Score: %4.24
- Published: Sep. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0721
Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.... Read more
Affected Products : pine- EPSS Score: %2.82
- Published: Sep. 17, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0715
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a differ... Read more
- EPSS Score: %61.98
- Published: Sep. 17, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0763
Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method parameter, as demonstrated using the PAGE parameter.... Read more
Affected Products : escapade- EPSS Score: %0.40
- Published: Sep. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0766
Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary code via (1) a long FTP banner, (2) a long response to a USER command, or (3) a long response to a PASS comm... Read more
Affected Products : ftp_desktop- EPSS Score: %6.73
- Published: Sep. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0767
Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers to cause a denial of service and execute arbitrary code via a client reques... Read more
- EPSS Score: %5.06
- Published: Sep. 17, 2003
- Modified: Apr. 03, 2025