Latest CVE Feed
-
7.2
HIGHCVE-2003-0597
Unknown vulnerability in display of Merge before 5.3.23a in UnixWare 7.1.x allows local users to gain root privileges.... Read more
Affected Products : openserver- EPSS Score: %0.08
- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0655
rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as a command line argument, which is modified while rscsi is running with privileges.... Read more
Affected Products : cdrtools- EPSS Score: %0.06
- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0633
Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without authentication, such as the GUEST user password and the... Read more
- EPSS Score: %0.62
- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0613
Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlier allows local users to execute arbitrary code via the high score file.... Read more
Affected Products : zblast- EPSS Score: %0.09
- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0654
Buffer overflow in autorespond may allow remote attackers to execute arbitrary code as the autorespond user via qmail.... Read more
Affected Products : autorespond- EPSS Score: %2.04
- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0532
Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a serv... Read more
- EPSS Score: %28.46
- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1063
The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.... Read more
- EPSS Score: %0.43
- Published: Aug. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1202
The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.... Read more
Affected Products : omail_webmail- EPSS Score: %4.04
- Published: Aug. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0519
Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.... Read more
Affected Products : internet_explorer- EPSS Score: %7.08
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0520
Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.... Read more
Affected Products : trillian- EPSS Score: %0.66
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0176
The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.... Read more
Affected Products : irix- EPSS Score: %0.66
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0572
Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).... Read more
Affected Products : irix- EPSS Score: %0.54
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0581
X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges ... Read more
Affected Products : xfstt- EPSS Score: %1.82
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0522
Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.... Read more
Affected Products : productcart- EPSS Score: %0.46
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2003-0578
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files.... Read more
Affected Products : u2_universe- EPSS Score: %0.03
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0557
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.... Read more
Affected Products : storefront- EPSS Score: %1.01
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0573
The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.... Read more
Affected Products : irix- EPSS Score: %0.69
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0142
Adobe Acrobat Reader (acroread) 6, under certain circumstances when running with the "Certified plug-ins only" option disabled, loads plug-ins with signatures used for older versions of Acrobat, which can allow attackers to cause Acrobat to enter Certifie... Read more
Affected Products : acrobat_reader- EPSS Score: %4.60
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0496
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.... Read more
- EPSS Score: %0.93
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0516
cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.... Read more
Affected Products : mgetty- EPSS Score: %0.90
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025