Latest CVE Feed
-
4.3
MEDIUMCVE-2003-0623
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.... Read more
- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0925
Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.... Read more
- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0935
Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.... Read more
- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0851
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.... Read more
- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0926
Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.... Read more
Affected Products : ethereal- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0933
Buffer overflow in conquest 7.2 and earlier may allow a local user to execute arbitrary code via a long environment variable.... Read more
Affected Products : conquest- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0934
Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.... Read more
Affected Products : pdt- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0927
Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.... Read more
- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1216
SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.... Read more
Affected Products : phpbb- Published: Nov. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1084
Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.... Read more
Affected Products : monit- Published: Nov. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1195
SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable.... Read more
Affected Products : vieboard- Published: Nov. 23, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1059
Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.... Read more
- Published: Nov. 20, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0846
SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on the .java_wrapper temporary file.... Read more
Affected Products : suse_linux- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0896
The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contain... Read more
Affected Products : jre- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0804
The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0870
Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.... Read more
Affected Products : opera_browser- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0898
IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.... Read more
Affected Products : db2_universal_database- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0847
SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.... Read more
Affected Products : suse_linux- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0897
"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications.... Read more
Affected Products : windows_xp- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0712
Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.... Read more
Affected Products : exchange_server- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025