Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 2.1

    LOW
    CVE-2003-0876

    Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than in... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %0.08
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1185

    Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.... Read more

    Affected Products : thwboard
    • EPSS Score: %1.14
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1196

    SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.... Read more

    Affected Products : vieboard
    • EPSS Score: %1.24
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2003-0855

    Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.... Read more

    Affected Products : linux pan
    • EPSS Score: %1.10
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-1192

    Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.... Read more

    Affected Products : ia_webmail_server
    • EPSS Score: %82.65
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0542

    Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 capt... Read more

    Affected Products : http_server
    • EPSS Score: %0.67
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0877

    Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.... Read more

    Affected Products : mac_os_x
    • EPSS Score: %0.07
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0883

    The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.... Read more

    Affected Products : mac_os_x
    • EPSS Score: %0.06
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0882

    Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.... Read more

    Affected Products : mac_os_x
    • EPSS Score: %0.50
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-0878

    slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.... Read more

    Affected Products : mac_os_x
    • EPSS Score: %0.11
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0901

    Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.... Read more

    Affected Products : postgresql
    • EPSS Score: %5.79
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0871

    Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %0.56
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-1190

    Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe.... Read more

    Affected Products : phprecipebook
    • EPSS Score: %0.43
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0895

    Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).... Read more

    Affected Products : mac_os_x
    • EPSS Score: %0.31
    • Published: Nov. 03, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-1187

    Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.... Read more

    Affected Products : phpkit
    • EPSS Score: %0.66
    • Published: Nov. 02, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1188

    Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.... Read more

    Affected Products : unichat
    • EPSS Score: %1.13
    • Published: Nov. 02, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1159

    Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.... Read more

    Affected Products : plug_and_play_web_server_proxy
    • EPSS Score: %1.00
    • Published: Oct. 31, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-1160

    FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).... Read more

    Affected Products : flexwatch_network_video_server
    • EPSS Score: %7.42
    • Published: Oct. 30, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-1197

    Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.... Read more

    Affected Products : ledforums
    • EPSS Score: %0.83
    • Published: Oct. 30, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-1194

    Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.... Read more

    Affected Products : booby
    • EPSS Score: %1.24
    • Published: Oct. 30, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 291827 Results