Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0036
Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value.... Read more
Affected Products : kerberos_5- EPSS Score: %19.01
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0048
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.... Read more
Affected Products : putty- EPSS Score: %0.08
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0046
AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.... Read more
Affected Products : absolutetelnet- EPSS Score: %0.09
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0669
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force authentication of incoming calls, which does not notify th... Read more
Affected Products : xpressa- EPSS Score: %0.44
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1328
The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security V... Read more
- EPSS Score: %43.56
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1405
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters... Read more
- EPSS Score: %14.08
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0060
Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos p... Read more
Affected Products : kerberos_5- EPSS Score: %9.13
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2003-0018
Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.... Read more
- EPSS Score: %0.07
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0059
Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.... Read more
Affected Products : kerberos_5- EPSS Score: %3.22
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0076
Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.... Read more
- EPSS Score: %0.71
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0074
Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.... Read more
Affected Products : plptools- EPSS Score: %0.85
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0062
Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.... Read more
Affected Products : nod32_antivirus- EPSS Score: %0.20
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0040
SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.... Read more
- EPSS Score: %0.49
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1326
Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."... Read more
- EPSS Score: %11.11
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1079
Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allo... Read more
- EPSS Score: %1.11
- Published: Feb. 18, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-1080
Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.... Read more
- EPSS Score: %0.08
- Published: Feb. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0027
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.... Read more
- EPSS Score: %65.15
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0002
Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.... Read more
Affected Products : content_management_server- EPSS Score: %12.99
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0016
Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.... Read more
Affected Products : http_server- EPSS Score: %39.52
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0043
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.... Read more
Affected Products : tomcat- EPSS Score: %2.26
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025