Latest CVE Feed
-
5.0
MEDIUMCVE-2003-0971
GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.... Read more
Affected Products : privacy_guard- EPSS Score: %2.34
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0824
Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain reque... Read more
Affected Products : windows_2000 windows_xp sharepoint_team_services frontpage_server_extensions iis- EPSS Score: %34.27
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0961
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.... Read more
Affected Products : linux_kernel- EPSS Score: %1.30
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0942
Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a long Name parameter to waadmin.wa.... Read more
Affected Products : sap_db- EPSS Score: %3.22
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0951
Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.... Read more
Affected Products : hp-ux- EPSS Score: %0.36
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0936
Symantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using AWHOST32.exe.... Read more
Affected Products : pcanywhere- EPSS Score: %0.07
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0974
Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users to a console, as demonstrated using appliedsnatch.c, or (2) add spurious IDS rules to sensors, as demonstrated using ... Read more
Affected Products : applied_watch_command_center- EPSS Score: %4.11
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0970
The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporarily disabled.... Read more
Affected Products : sun_fire- EPSS Score: %0.66
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0327
Sybase Adaptive Server Enterprise (ASE) 12.5 allows remote attackers to cause a denial of service (hang) via a remote password array with an invalid length, which triggers a heap-based buffer overflow.... Read more
Affected Products : adaptive_server_enterprise- EPSS Score: %0.81
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0938
vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which is found and loaded by SAP DB before the real DLL, as demonstrated using the... Read more
Affected Products : sap_db- EPSS Score: %0.05
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0947
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.... Read more
Affected Products : wireless_tools- EPSS Score: %0.09
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0795
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to th... Read more
- EPSS Score: %8.01
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0962
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.... Read more
- EPSS Score: %41.86
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0812
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated usin... Read more
- EPSS Score: %81.92
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0941
web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.... Read more
Affected Products : sap_db- EPSS Score: %1.30
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0940
Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.... Read more
Affected Products : sap_db- EPSS Score: %0.90
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0628
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.... Read more
Affected Products : peopletools- EPSS Score: %0.50
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0955
OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2... Read more
Affected Products : openbsd- EPSS Score: %0.44
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0967
rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password a... Read more
Affected Products : freeradius- EPSS Score: %4.40
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2003-0856
iproute 2.4.7 and earlier allows local users to cause a denial of service via spoofed messages as other users to the kernel netlink interface.... Read more
- EPSS Score: %0.05
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025