Latest CVE Feed
-
7.5
HIGHCVE-2003-0559
mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : phpforum- EPSS Score: %0.75
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0588
admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.... Read more
Affected Products : digi-news- EPSS Score: %2.56
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2003-0590
Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.... Read more
Affected Products : splatt_forum- EPSS Score: %1.25
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0352
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.... Read more
- EPSS Score: %89.81
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2003-0536
Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng paramete... Read more
Affected Products : phpsysinfo- EPSS Score: %0.74
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0522
Multiple SQL injection vulnerabilities in ProductCart 1.5 through 2 allow remote attackers to (1) gain access to the admin control panel via the idadmin parameter to login.asp or (2) gain other privileges via the Email parameter to Custva.asp.... Read more
Affected Products : productcart- EPSS Score: %0.46
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0539
skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.... Read more
- EPSS Score: %0.07
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0523
Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.... Read more
Affected Products : productcart- EPSS Score: %0.40
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0254
Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.... Read more
Affected Products : http_server- EPSS Score: %11.72
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0554
NeoModus Direct Connect 1.0 build 9, and possibly other versions, allows remote attackers to cause a denial of service (connection and possibly memory exhaustion) via a flood of ConnectToMe requests containing arbitrary IP addresses and ports.... Read more
Affected Products : direct_connect- EPSS Score: %0.66
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0577
mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which creates a negative frame size.... Read more
Affected Products : mpg123- EPSS Score: %5.24
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0192
Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could ... Read more
Affected Products : http_server- EPSS Score: %20.66
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0176
The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.... Read more
Affected Products : irix- EPSS Score: %0.66
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-1263
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as s... Read more
Affected Products : metamail- EPSS Score: %0.32
- Published: Aug. 15, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1088
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.... Read more
Affected Products : zorum- EPSS Score: %0.53
- Published: Aug. 11, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0503
Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.... Read more
Affected Products : windows_2000- EPSS Score: %10.58
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0449
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or... Read more
Affected Products : database- EPSS Score: %0.04
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0493
Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.... Read more
Affected Products : snitz_forums_2000- EPSS Score: %0.46
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0490
The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs wi... Read more
Affected Products : retrospect_client- EPSS Score: %0.04
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0485
Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.... Read more
Affected Products : 4gl_compiler- EPSS Score: %0.35
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025