Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2003-0400

    Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred ... Read more

    Affected Products : content_suite storyserver vignette
    • EPSS Score: %2.43
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0417

    Directory traversal vulnerability in Son hServer 0.2 allows remote attackers to read arbitrary files via ".|." (modified dot-dot) sequences.... Read more

    Affected Products : son_hserver
    • EPSS Score: %1.38
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0416

    Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in ... Read more

    Affected Products : bandmin
    • EPSS Score: %0.52
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0411

    Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.... Read more

    • EPSS Score: %10.05
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0407

    Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.... Read more

    Affected Products : batalla_naval
    • EPSS Score: %3.93
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0408

    Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.... Read more

    Affected Products : upclient
    • EPSS Score: %0.32
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0414

    The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.... Read more

    Affected Products : one_application_server
    • EPSS Score: %0.05
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0410

    Buffer overflow in AnalogX Proxy 4.13 allows remote attackers to execute arbitrary code via a long URL to port 6588.... Read more

    Affected Products : proxy
    • EPSS Score: %8.39
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-0404

    Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login ... Read more

    Affected Products : content_suite storyserver vignette
    • EPSS Score: %0.42
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0415

    Remote PC Access Server 2.2 allows remote attackers to cause a denial of service (crash) by receiving packets from the server and sending them back to the server.... Read more

    Affected Products : remote_pc_access
    • EPSS Score: %0.89
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0413

    Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP r... Read more

    Affected Products : one_application_server
    • EPSS Score: %1.68
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0412

    Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.... Read more

    Affected Products : one_application_server
    • EPSS Score: %1.09
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1067

    Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %0.09
    • Published: Jun. 19, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1086

    PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the ... Read more

    Affected Products : pmachine_pro pmachine_free
    • EPSS Score: %1.60
    • Published: Jun. 17, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1565

    Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.... Read more

    Affected Products : immunix
    • EPSS Score: %0.94
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2003-0279

    Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.... Read more

    Affected Products : php-nuke
    • EPSS Score: %0.02
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0286

    SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.... Read more

    Affected Products : snitz_forums_2000
    • EPSS Score: %1.23
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0354

    Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.... Read more

    Affected Products : linux
    • EPSS Score: %0.82
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0310

    Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.... Read more

    Affected Products : ez_publish
    • EPSS Score: %0.37
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0297

    c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer si... Read more

    Affected Products : pine c-client imap-2002b
    • EPSS Score: %0.91
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 291205 Results