Latest CVE Feed
-
7.5
HIGHCVE-2003-0805
Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.... Read more
Affected Products : gopherd- EPSS Score: %5.56
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0682
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.... Read more
Affected Products : openssh- EPSS Score: %0.42
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0803
Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.... Read more
Affected Products : electronic_documentation- EPSS Score: %2.01
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0801
Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.... Read more
Affected Products : electronic_documentation- EPSS Score: %0.31
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0690
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5... Read more
Affected Products : kde- EPSS Score: %2.08
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1567
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.... Read more
Affected Products : tomcat- EPSS Score: %48.22
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0695
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vu... Read more
Affected Products : openssh- EPSS Score: %1.17
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0692
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.... Read more
Affected Products : kde- EPSS Score: %1.21
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0759
Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.... Read more
Affected Products : db2_universal_database- EPSS Score: %0.16
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-1053
Multiple buffer overflows in XShisen allow attackers to execute arbitrary code via a long (1) -KCONV command line option or (2) XSHISENLIB environment variable.... Read more
Affected Products : xshisen- EPSS Score: %0.24
- Published: Oct. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0771
Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.... Read more
Affected Products : apache_gallery- EPSS Score: %0.09
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0770
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.... Read more
Affected Products : ikonboard- EPSS Score: %10.91
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0775
saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).... Read more
- EPSS Score: %1.58
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0777
saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).... Read more
- EPSS Score: %0.83
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0778
saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).... Read more
- EPSS Score: %0.83
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0768
Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.... Read more
Affected Products : asp.net- EPSS Score: %17.17
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0693
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-200... Read more
Affected Products : openssh- EPSS Score: %32.68
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2003-0780
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.... Read more
- EPSS Score: %70.05
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0722
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.... Read more
Affected Products : solaris- EPSS Score: %89.40
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0773
saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.... Read more
- EPSS Score: %1.27
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025