Latest CVE Feed
-
5.8
MEDIUMCVE-2002-1533
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).... Read more
Affected Products : jetty- EPSS Score: %2.91
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1543
Buffer overflow in trek on NetBSD 1.5 through 1.5.3 allows local users to gain privileges via long keyboard input.... Read more
Affected Products : netbsd- EPSS Score: %0.09
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1560
index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.... Read more
Affected Products : gbook- EPSS Score: %2.36
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0147
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of ... Read more
- EPSS Score: %21.35
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0145
Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.... Read more
Affected Products : tcpdump- EPSS Score: %1.27
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1529
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter.... Read more
Affected Products : superscout_email_filter- EPSS Score: %0.88
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1557
Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.... Read more
Affected Products : optical_networking_systems_software- EPSS Score: %0.49
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1552
Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager.... Read more
Affected Products : edirectory- EPSS Score: %0.21
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1544
Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get.... Read more
Affected Products : personal_ftp_server- EPSS Score: %0.35
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0127
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.... Read more
Affected Products : linux_kernel- EPSS Score: %0.95
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0144
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) ... Read more
- EPSS Score: %0.25
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1074
Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.... Read more
Affected Products : solaris- EPSS Score: %0.05
- Published: Mar. 28, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certa... Read more
- EPSS Score: %56.05
- Published: Mar. 25, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0129
Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.... Read more
- EPSS Score: %19.35
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0138
Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.... Read more
Affected Products : kerberos- EPSS Score: %5.64
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2003-0150
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifyin... Read more
Affected Products : mysql- EPSS Score: %12.81
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0151
BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.... Read more
Affected Products : weblogic_server- EPSS Score: %4.73
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0011
Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming... Read more
Affected Products : isa_server- EPSS Score: %18.32
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0128
The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggerin... Read more
- EPSS Score: %25.27
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0139
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste ... Read more
Affected Products : kerberos- EPSS Score: %4.95
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025