Latest CVE Feed
-
4.3
MEDIUMCVE-2004-0091
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. ... Read more
Affected Products : vbulletin- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0064
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.... Read more
Affected Products : suse_linux- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0063
The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by acceptin... Read more
Affected Products : payshield_spp_library- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0073
PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote attackers to execute arbitrary PHP code by modifying the edp_relative_path parameter to reference a URL on a remote web server that co... Read more
Affected Products : easydynamicpages- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0049
Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.... Read more
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0061
WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.... Read more
Affected Products : www_file_share_pro- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0072
Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.... Read more
Affected Products : accipiter_direct_server- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0074
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, or (2) a long -xsokdir command line argument, a different vulnerability than CVE-2003-0949.... Read more
Affected Products : xsok- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0988
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.... Read more
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0004
The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trus... Read more
Affected Products : openca- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1031
Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote attackers to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (2) "Biography", or (3) "Occupation."... Read more
Affected Products : vbulletin- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0989
tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.... Read more
- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0700
The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-... Read more
Affected Products : kernel- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2003-0924
netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.... Read more
Affected Products : netpbm- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0965
Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.... Read more
Affected Products : mailman- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1030
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.... Read more
Affected Products : mini_remote_control_server- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0992
Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.... Read more
Affected Products : mailman- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1029
The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a packet with invalid data to UDP port 1701, which causes l2tp_avp_print to use a bad length value when c... Read more
Affected Products : tcpdump- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1032
Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly in... Read more
Affected Products : pi3web- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0903
Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.... Read more
Affected Products : data_access_components- Published: Feb. 17, 2004
- Modified: Apr. 03, 2025