Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.6

    MEDIUM
    CVE-2003-0451

    Multiple buffer overflows in xbl before 1.0k allow local users to gain privileges via certain long command line arguments.... Read more

    Affected Products : xbl
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0450

    Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer ov... Read more

    Affected Products : radius_daemon
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0452

    Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."... Read more

    Affected Products : osh
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0509

    SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.... Read more

    Affected Products : eshop
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0454

    Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.... Read more

    Affected Products : xgalaga
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0492

    Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.... Read more

    Affected Products : snitz_forums_2000
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0478

    Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attacke... Read more

    Affected Products : adromedeircd methane digatech ircd-ru ircd
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-0495

    Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.... Read more

    Affected Products : lednews
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0498

    Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.... Read more

    Affected Products : cache_database
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0505

    Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.... Read more

    Affected Products : netmeeting
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0506

    Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.... Read more

    Affected Products : netmeeting
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0471

    Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.... Read more

    Affected Products : webadmin
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0500

    SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.... Read more

    Affected Products : proftpd
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0474

    Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.... Read more

    Affected Products : iweb_server
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0472

    The IPv6 capability in IRIX 6.5.19 allows remote attackers to cause a denial of service (hang) in inetd via port scanning.... Read more

    Affected Products : irix
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0510

    Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.... Read more

    Affected Products : ezbounce
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0489

    tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.... Read more

    Affected Products : tcptraceroute
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0487

    Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl ... Read more

    Affected Products : kerio_mailserver
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0493

    Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.... Read more

    Affected Products : snitz_forums_2000
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0477

    wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.... Read more

    Affected Products : wzdftpd
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 292811 Results