Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2003-0139

    Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste ... Read more

    Affected Products : kerberos
    • EPSS Score: %4.95
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0131

    The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 ... Read more

    Affected Products : openssl
    • EPSS Score: %17.25
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0156

    Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.... Read more

    Affected Products : lxr
    • EPSS Score: %0.41
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 9.0

    HIGH
    CVE-2003-0150

    MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifyin... Read more

    Affected Products : mysql
    • EPSS Score: %12.81
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0151

    BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.... Read more

    Affected Products : weblogic_server
    • EPSS Score: %4.73
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1201

    ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of ser... Read more

    Affected Products : openldap
    • EPSS Score: %0.28
    • Published: Mar. 20, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-1203

    Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.... Read more

    Affected Products : mambo_site_server
    • EPSS Score: %0.52
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-1095

    BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access witho... Read more

    Affected Products : weblogic_server
    • EPSS Score: %0.13
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0123

    Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.... Read more

    Affected Products : lotus_domino lotus_notes_client
    • EPSS Score: %4.14
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0122

    Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of t... Read more

    Affected Products : lotus_domino lotus_notes_client
    • EPSS Score: %22.97
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0081

    Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.... Read more

    Affected Products : linux ethereal
    • EPSS Score: %4.70
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0387

    Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL.... Read more

    Affected Products : one_application_server
    • EPSS Score: %3.85
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0020

    Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.... Read more

    Affected Products : http_server
    • EPSS Score: %32.16
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0102

    Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).... Read more

    Affected Products : netbsd file
    • EPSS Score: %8.28
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0143

    The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.... Read more

    Affected Products : qpopper
    • EPSS Score: %9.13
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0125

    Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.... Read more

    Affected Products : routefinder_550_vpn
    • EPSS Score: %10.05
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0124

    man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in t... Read more

    Affected Products : man
    • EPSS Score: %1.89
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0104

    Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.... Read more

    Affected Products : peopletools
    • EPSS Score: %1.39
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0137

    SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.... Read more

    Affected Products : sgsn_dx200
    • EPSS Score: %0.59
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0121

    Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.... Read more

    Affected Products : mailsweeper
    • EPSS Score: %4.41
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 291157 Results