Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2003-0028

    Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certa... Read more

    Affected Products : aix solaris hp-ux sunos freebsd glibc openafs kerberos_5 openbsd unicos +3 more products
    • EPSS Score: %56.05
    • Published: Mar. 25, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0129

    Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.... Read more

    Affected Products : linux evolution
    • EPSS Score: %19.35
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0151

    BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.... Read more

    Affected Products : weblogic_server
    • EPSS Score: %4.73
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0138

    Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.... Read more

    Affected Products : kerberos
    • EPSS Score: %5.64
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0156

    Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.... Read more

    Affected Products : lxr
    • EPSS Score: %0.41
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0130

    The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded imag... Read more

    Affected Products : linux evolution
    • EPSS Score: %14.82
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0010

    Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large ar... Read more

    • EPSS Score: %18.90
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 9.0

    HIGH
    CVE-2003-0150

    MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifyin... Read more

    Affected Products : mysql
    • EPSS Score: %12.81
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0140

    Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary co... Read more

    Affected Products : mutt linux
    • EPSS Score: %1.90
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0011

    Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming... Read more

    Affected Products : isa_server
    • EPSS Score: %18.32
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0128

    The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggerin... Read more

    Affected Products : linux evolution
    • EPSS Score: %25.27
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0131

    The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 ... Read more

    Affected Products : openssl
    • EPSS Score: %17.25
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0139

    Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste ... Read more

    Affected Products : kerberos
    • EPSS Score: %4.95
    • Published: Mar. 24, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1201

    ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of ser... Read more

    Affected Products : openldap
    • EPSS Score: %0.28
    • Published: Mar. 20, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0125

    Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.... Read more

    Affected Products : routefinder_550_vpn
    • EPSS Score: %10.05
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-1203

    Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.... Read more

    Affected Products : mambo_site_server
    • EPSS Score: %0.52
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0143

    The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.... Read more

    Affected Products : qpopper
    • EPSS Score: %9.13
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0102

    Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).... Read more

    Affected Products : netbsd file
    • EPSS Score: %8.28
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0081

    Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.... Read more

    Affected Products : linux ethereal
    • EPSS Score: %4.70
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0387

    Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL.... Read more

    Affected Products : one_application_server
    • EPSS Score: %3.85
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 291205 Results