Latest CVE Feed
-
7.5
HIGHCVE-2003-1185
Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.... Read more
Affected Products : thwboard- EPSS Score: %1.14
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0876
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than in... Read more
- EPSS Score: %0.08
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0789
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.... Read more
Affected Products : http_server- EPSS Score: %10.11
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2003-0899
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences... Read more
Affected Products : thttpd- EPSS Score: %36.22
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2003-0855
Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.... Read more
- EPSS Score: %1.10
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0683
NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.... Read more
Affected Products : irix- EPSS Score: %0.49
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0878
slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.... Read more
Affected Products : mac_os_x- EPSS Score: %0.11
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0877
Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.... Read more
Affected Products : mac_os_x- EPSS Score: %0.07
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0883
The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.... Read more
Affected Products : mac_os_x- EPSS Score: %0.06
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1187
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.... Read more
Affected Products : phpkit- EPSS Score: %0.66
- Published: Nov. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1188
Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.... Read more
Affected Products : unichat- EPSS Score: %1.13
- Published: Nov. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1159
Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.... Read more
Affected Products : plug_and_play_web_server_proxy- EPSS Score: %1.00
- Published: Oct. 31, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1194
Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.... Read more
Affected Products : booby- EPSS Score: %1.24
- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1160
FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).... Read more
Affected Products : flexwatch_network_video_server- EPSS Score: %7.42
- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1143
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.... Read more
Affected Products : serioussam- EPSS Score: %8.10
- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1197
Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.... Read more
Affected Products : ledforums- EPSS Score: %0.83
- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1186
Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.... Read more
Affected Products : simplewebserver- EPSS Score: %5.51
- Published: Oct. 29, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1191
chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.... Read more
Affected Products : e107- EPSS Score: %5.22
- Published: Oct. 29, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1189
Unknown vulnerability in Nokia IPSO 3.7, configured as IP Clusters, allows remote attackers to cause a denial of service via unknown attack vectors.... Read more
Affected Products : ipso- EPSS Score: %0.91
- Published: Oct. 29, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-1183
The WebCache component in Oracle Files 9.0.3.1.0, 9.0.3.2.0, and 9.0.3.3.0 of Oracle Collaboration Suite Release 1 caches files despite the cacheability rules imposed by Oracle Files, which allows local users to gain access.... Read more
Affected Products : oracle_files- EPSS Score: %0.27
- Published: Oct. 28, 2003
- Modified: Apr. 03, 2025