Latest CVE Feed
-
7.5
HIGHCVE-2003-0249
PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: thi... Read more
Affected Products : php- EPSS Score: %0.40
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0317
iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.... Read more
Affected Products : iisprotect- EPSS Score: %3.50
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1480
MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.... Read more
- EPSS Score: %16.14
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1204
Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.12 BETA and earlier allow remote attackers to execute script on other clients via (1) the link parameter in sectionswindow.php, the directory parameter in (2) gallery.php, (3) na... Read more
Affected Products : mambo_site_server- EPSS Score: %9.20
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1469
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error mes... Read more
- EPSS Score: %1.50
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1121
Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary con... Read more
Affected Products : scriptlogic- EPSS Score: %4.96
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1414
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.... Read more
- EPSS Score: %2.66
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1200
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.... Read more
Affected Products : mdaemon- EPSS Score: %59.89
- Published: Dec. 29, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-1215
SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.... Read more
Affected Products : phpbb- EPSS Score: %0.06
- Published: Dec. 29, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1198
connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field.... Read more
Affected Products : cherokee_httpd- EPSS Score: %0.80
- Published: Dec. 26, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0976
NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.... Read more
Affected Products : netware- EPSS Score: %0.26
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0972
Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) characters in escape sequences, which leads to a buffer overflow.... Read more
Affected Products : screen- EPSS Score: %1.21
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0940
Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.... Read more
Affected Products : sap_db- EPSS Score: %0.90
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0943
web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially sensitive information or redirect attacks against internal databases via (1) waecho, (2) Web SQL Interface... Read more
Affected Products : sap_db- EPSS Score: %0.90
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0932
Buffer overflow in omega-rpg 0.90 allows local users to execute arbitrary code via a long (1) command line or (2) environment variable.... Read more
Affected Products : omega-rpg- EPSS Score: %0.09
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0955
OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2... Read more
Affected Products : openbsd- EPSS Score: %0.44
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0937
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which lea... Read more
- EPSS Score: %0.09
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0975
Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.... Read more
- EPSS Score: %0.58
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0951
Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.... Read more
Affected Products : hp-ux- EPSS Score: %0.36
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0821
Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.... Read more
- EPSS Score: %10.98
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025