Latest CVE Feed
-
4.6
MEDIUMCVE-2003-0102
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).... Read more
- EPSS Score: %8.28
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0124
man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in t... Read more
Affected Products : man- EPSS Score: %1.89
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0081
Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.... Read more
- EPSS Score: %4.70
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0020
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.... Read more
Affected Products : http_server- EPSS Score: %32.16
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0069
The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, whi... Read more
Affected Products : putty- EPSS Score: %0.35
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0067
The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, whi... Read more
Affected Products : aterm- EPSS Score: %0.72
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0125
Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.... Read more
Affected Products : routefinder_550_vpn- EPSS Score: %10.05
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0143
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.... Read more
Affected Products : qpopper- EPSS Score: %9.13
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0104
Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.... Read more
Affected Products : peopletools- EPSS Score: %1.39
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0137
SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.... Read more
Affected Products : sgsn_dx200- EPSS Score: %0.59
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0121
Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.... Read more
Affected Products : mailsweeper- EPSS Score: %4.41
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0126
The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.... Read more
Affected Products : routefinder_550_vpn- EPSS Score: %0.47
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0030
Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select... Read more
Affected Products : secure.data- EPSS Score: %5.69
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0387
Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL.... Read more
Affected Products : one_application_server- EPSS Score: %3.85
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0077
The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when th... Read more
Affected Products : hanterm-xf- EPSS Score: %0.67
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-1095
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access witho... Read more
Affected Products : weblogic_server- EPSS Score: %0.13
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0123
Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.... Read more
- EPSS Score: %4.14
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0052
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.... Read more
- EPSS Score: %0.76
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0053
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an e... Read more
- EPSS Score: %0.39
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- EPSS Score: %0.18
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025