Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2003-1136

    Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL.... Read more

    Affected Products : chi_kien_uong_guestbook
    • EPSS Score: %1.89
    • Published: Oct. 23, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0702

    Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server ... Read more

    Affected Products : realsecure_server_sensor
    • EPSS Score: %1.98
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0749

    Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.... Read more

    Affected Products : internet_transaction_server
    • EPSS Score: %5.52
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0751

    SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.... Read more

    Affected Products : py-membres
    • EPSS Score: %0.52
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0732

    CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.... Read more

    • EPSS Score: %0.38
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0724

    ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.... Read more

    Affected Products : tru64
    • EPSS Score: %0.30
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0709

    Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.... Read more

    Affected Products : whois
    • EPSS Score: %2.86
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0745

    SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.... Read more

    Affected Products : snmpc
    • EPSS Score: %0.87
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0755

    Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.... Read more

    Affected Products : gtkftp
    • EPSS Score: %4.46
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0747

    wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~lang... Read more

    Affected Products : internet_transaction_server
    • EPSS Score: %6.86
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0658

    Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.... Read more

    • EPSS Score: %0.39
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0665

    Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.... Read more

    Affected Products : access
    • EPSS Score: %35.65
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0729

    Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.... Read more

    Affected Products : tftpdnt
    • EPSS Score: %5.39
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0739

    VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.... Read more

    Affected Products : workstation
    • EPSS Score: %0.07
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0347

    Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.... Read more

    Affected Products : office project visual_basic visio
    • EPSS Score: %70.46
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0723

    Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.... Read more

    Affected Products : gkrellm
    • EPSS Score: %7.54
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0686

    Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.... Read more

    Affected Products : pam_smb pam_smb
    • EPSS Score: %41.40
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0630

    Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line arguments, as demonstrated with the -osa_rom argument.... Read more

    Affected Products : atari800
    • EPSS Score: %0.05
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2003-0738

    The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.... Read more

    Affected Products : phpwebsite
    • EPSS Score: %0.60
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0757

    Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.... Read more

    Affected Products : firewall-1
    • EPSS Score: %3.62
    • Published: Oct. 20, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 291672 Results