Latest CVE Feed
-
4.3
MEDIUMCVE-2003-1149
Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page.... Read more
Affected Products : norton_internet_security- EPSS Score: %2.00
- Published: Oct. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1139
Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.... Read more
Affected Products : musicqueue- EPSS Score: %2.46
- Published: Oct. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1060
The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.... Read more
- EPSS Score: %0.74
- Published: Oct. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1137
Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.... Read more
Affected Products : sh-httpd- EPSS Score: %6.47
- Published: Oct. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1181
Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.... Read more
Affected Products : advanced_poll- EPSS Score: %7.54
- Published: Oct. 25, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1148
Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_... Read more
Affected Products : les_visiteurs- EPSS Score: %8.38
- Published: Oct. 25, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1136
Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.... Read more
Affected Products : chi_kien_uong_guestbook- EPSS Score: %1.89
- Published: Oct. 23, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0732
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.... Read more
- EPSS Score: %0.38
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0709
Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.... Read more
Affected Products : whois- EPSS Score: %2.86
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0751
SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.... Read more
Affected Products : py-membres- EPSS Score: %0.52
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0726
RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated u... Read more
- EPSS Score: %9.58
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0749
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.... Read more
Affected Products : internet_transaction_server- EPSS Score: %5.52
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0702
Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server ... Read more
Affected Products : realsecure_server_sensor- EPSS Score: %1.98
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0724
ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.... Read more
Affected Products : tru64- EPSS Score: %0.30
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0658
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.... Read more
- EPSS Score: %0.39
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0745
SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.... Read more
Affected Products : snmpc- EPSS Score: %0.87
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0755
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.... Read more
Affected Products : gtkftp- EPSS Score: %4.46
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0747
wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~lang... Read more
Affected Products : internet_transaction_server- EPSS Score: %6.86
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0347
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.... Read more
- EPSS Score: %70.46
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0688
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Se... Read more
- EPSS Score: %1.71
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025