Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2003-1138

    The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash ... Read more

    Affected Products : linux interchange
    • EPSS Score: %3.18
    • Published: Oct. 27, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1181

    Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.... Read more

    Affected Products : advanced_poll
    • EPSS Score: %7.54
    • Published: Oct. 25, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1148

    Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_... Read more

    Affected Products : les_visiteurs
    • EPSS Score: %8.38
    • Published: Oct. 25, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-1136

    Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.... Read more

    Affected Products : chi_kien_uong_guestbook
    • EPSS Score: %1.89
    • Published: Oct. 23, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0724

    ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.... Read more

    Affected Products : tru64
    • EPSS Score: %0.30
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0702

    Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server ... Read more

    Affected Products : realsecure_server_sensor
    • EPSS Score: %1.98
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0732

    CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.... Read more

    • EPSS Score: %0.38
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0751

    SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.... Read more

    Affected Products : py-membres
    • EPSS Score: %0.52
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0709

    Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.... Read more

    Affected Products : whois
    • EPSS Score: %2.86
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2003-0726

    RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated u... Read more

    • EPSS Score: %9.58
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0749

    Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.... Read more

    Affected Products : internet_transaction_server
    • EPSS Score: %5.52
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0754

    nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.... Read more

    Affected Products : newsphp
    • EPSS Score: %0.40
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0708

    Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.... Read more

    Affected Products : linuxnode
    • EPSS Score: %0.91
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0733

    Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) ... Read more

    • EPSS Score: %0.97
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0735

    SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.... Read more

    Affected Products : phpwebsite
    • EPSS Score: %1.05
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0743

    Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL charac... Read more

    Affected Products : exim
    • EPSS Score: %7.02
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0756

    Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.... Read more

    Affected Products : sitebuilder
    • EPSS Score: %0.39
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0747

    wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~lang... Read more

    Affected Products : internet_transaction_server
    • EPSS Score: %6.86
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0745

    SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.... Read more

    Affected Products : snmpc
    • EPSS Score: %0.87
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-0727

    Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.... Read more

    Affected Products : database_server
    • EPSS Score: %85.76
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 291615 Results