Latest CVE Feed
-
7.5
HIGHCVE-2003-0321
Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled... Read more
Affected Products : bitchx- EPSS Score: %1.22
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0318
Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.... Read more
Affected Products : php-nuke- EPSS Score: %0.02
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0305
The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.... Read more
Affected Products : ios- EPSS Score: %0.66
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2003-0332
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats exte... Read more
Affected Products : badblue- EPSS Score: %1.98
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0362
Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.... Read more
Affected Products : debian_linux- EPSS Score: %0.45
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0324
Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2)... Read more
Affected Products : epic4- EPSS Score: %0.93
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0224
Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overr... Read more
- EPSS Score: %15.45
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1462
details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.... Read more
Affected Products : php-affiliate- EPSS Score: %1.15
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0242
IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not explicitly allowed by the policies.... Read more
Affected Products : mac_os_x- EPSS Score: %1.40
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0309
Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file... Read more
Affected Products : internet_explorer- EPSS Score: %15.05
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1460
L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.... Read more
Affected Products : l-forum- EPSS Score: %1.41
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0326
Integer overflow in parse_decode_path() of slocate may allow attackers to execute arbitrary code via a LOCATE_PATH with a large number of ":" (colon) characters, whose count is used in a call to malloc.... Read more
Affected Products : slocate- EPSS Score: %0.10
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1458
Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.... Read more
Affected Products : l-forum- EPSS Score: %0.87
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1456
Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.... Read more
Affected Products : mirc- EPSS Score: %15.10
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1454
MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.... Read more
Affected Products : mywebserver- EPSS Score: %0.66
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0306
Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.... Read more
Affected Products : windows_xp- EPSS Score: %2.48
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0303
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.... Read more
Affected Products : oneorzero_helpdesk- EPSS Score: %0.33
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0329
CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.... Read more
Affected Products : cesarftp- EPSS Score: %0.14
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0194
tcpdump does not properly drop privileges to the pcap user when starting up.... Read more
- EPSS Score: %0.07
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0189
The authentication module for Apache 2.0.40 through 2.0.45 on Unix does not properly handle threads safely when using the crypt_r or crypt functions, which allows remote attackers to cause a denial of service (failed Basic authentication with valid userna... Read more
Affected Products : http_server- EPSS Score: %19.41
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025