Latest CVE Feed
-
5.0
MEDIUMCVE-2003-0475
Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.... Read more
Affected Products : iweb_server- EPSS Score: %1.26
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0507
Stack-based buffer overflow in Active Directory in Windows 2000 before SP4 allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via an LDAP version 3 search request with a large number of (1) "AND," (2) "OR," a... Read more
Affected Products : windows_2000- EPSS Score: %31.20
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0504
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module.... Read more
Affected Products : phpgroupware- EPSS Score: %0.45
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0500
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.... Read more
Affected Products : proftpd- EPSS Score: %1.56
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0497
Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.... Read more
Affected Products : cache_database- EPSS Score: %0.11
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0484
Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.... Read more
Affected Products : phpbb- EPSS Score: %0.87
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0478
Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attacke... Read more
- EPSS Score: %5.55
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2003-0499
Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.... Read more
Affected Products : mantis- EPSS Score: %0.11
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0453
traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overfl... Read more
Affected Products : traceroute-nanog- EPSS Score: %1.13
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0495
Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.... Read more
Affected Products : lednews- EPSS Score: %0.57
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0492
Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.... Read more
Affected Products : snitz_forums_2000- EPSS Score: %0.52
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0488
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.... Read more
Affected Products : kerio_mailserver- EPSS Score: %0.85
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0481
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.... Read more
Affected Products : tutos- EPSS Score: %0.40
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1205
Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name.... Read more
Affected Products : crob_ftp_server- EPSS Score: %0.91
- Published: Aug. 06, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0643
Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Jul. 25, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0436
Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.... Read more
Affected Products : mnogosearch- EPSS Score: %12.75
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0348
A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script.... Read more
- EPSS Score: %27.59
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0435
Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.... Read more
Affected Products : typespeed- EPSS Score: %3.28
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0437
Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.... Read more
Affected Products : mnogosearch- EPSS Score: %5.43
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-0438
eldav WebDAV client for Emacs, version 0.7.2 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : eldav- EPSS Score: %0.08
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025