Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2004-1942

    The Solaris 9 patches 113579-02 through 113579-05, and 114342-02 through 114342-05, prevent ypserv and ypxfrd from properly restricting access to secure NIS maps, which allows local users to use ypcat or ypmatch to extract the contents of a secure map suc... Read more

    Affected Products : solaris patch_manager
    • Published: Apr. 19, 2004
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2004-1935

    Cross-site scripting (XSS) vulnerability in SCT Campus Pipeline allows remote attackers to inject arbitrary web script or HTML via onload, onmouseover, and other Javascript events in an e-mail attachment.... Read more

    Affected Products : campus_pipeline
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1035

    The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.... Read more

    Affected Products : sapgui sap_r_3
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1577

    SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM accounts.... Read more

    Affected Products : sap_r_3
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1578

    The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is no... Read more

    Affected Products : sap_r_3
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-1576

    lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver prog... Read more

    Affected Products : sap_db
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1579

    SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error.... Read more

    Affected Products : sapgui
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0364

    The WrapNISUM ActiveX component (WrapUM.dll) in Norton Internet Security 2004 is marked safe for scripting, which allows remote attackers to execute arbitrary programs via the LaunchURL method.... Read more

    Affected Products : norton_internet_security
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2004-0122

    Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.... Read more

    Affected Products : msn_messenger
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0372

    xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.... Read more

    Affected Products : xine
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-1040

    kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of service (crash) by sending certain signals to kmod.... Read more

    Affected Products : linux_kernel
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0362

    Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI respon... Read more

    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0363

    Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method... Read more

    Affected Products : norton_antispam
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0152

    Multiple stack-based buffer overflows in (1) the encode_mime function, (2) the encode_uuencode function, (3) or the decode_uuencode function for emil 2.1.0 and earlier allow remote attackers to execute arbitrary code via e-mail messages containing attachm... Read more

    Affected Products : emil
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-1034

    The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.... Read more

    Affected Products : sap_db
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2004-0148

    wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.... Read more

    Affected Products : propack wu-ftpd
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2004-0108

    The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.... Read more

    Affected Products : propack sysstat sysstat
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1037

    Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."... Read more

    Affected Products : internet_transaction_server
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2004-0153

    Multiple format string vulnerabilities in emil 2.1.0 and earlier may allow remote attackers to execute arbitrary code by triggering certain error messages.... Read more

    Affected Products : emil
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
  • 7.0

    HIGH
    CVE-2004-0217

    The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.... Read more

    Affected Products : linux antivirus_scan_engine
    • Published: Apr. 15, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 293555 Results