Latest CVE Feed
-
7.5
HIGHCVE-2003-0152
Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.... Read more
Affected Products : bonsai- EPSS Score: %0.90
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0083
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to ... Read more
Affected Products : http_server- EPSS Score: %13.39
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0072
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an arr... Read more
- EPSS Score: %1.25
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0082
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (ak... Read more
- EPSS Score: %2.54
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0141
The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed d... Read more
- EPSS Score: %0.24
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0030
The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.... Read more
- EPSS Score: %0.22
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0106
The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.... Read more
Affected Products : enterprise_firewall- EPSS Score: %0.75
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1488
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian user is not in.... Read more
Affected Products : trillian- EPSS Score: %4.38
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1502
Symbolic link vulnerability in xbreaky before 0.5.5 allows local users to overwrite arbitrary files via a symlink from the user's .breakyhighscores file to the target file.... Read more
Affected Products : xbreaky- EPSS Score: %0.18
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1526
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field.... Read more
Affected Products : emu_webmail- EPSS Score: %0.69
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2003-0160
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.... Read more
- EPSS Score: %0.54
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1494
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.... Read more
Affected Products : html_os- EPSS Score: %0.52
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1489
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.... Read more
Affected Products : planetweb- EPSS Score: %7.96
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0165
Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.... Read more
- EPSS Score: %0.75
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0155
bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.... Read more
Affected Products : bonsai- EPSS Score: %0.58
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0080
The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.... Read more
- EPSS Score: %0.44
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0145
Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.... Read more
Affected Products : tcpdump- EPSS Score: %1.27
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1539
Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.... Read more
Affected Products : mdaemon- EPSS Score: %4.30
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0127
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.... Read more
Affected Products : linux_kernel- EPSS Score: %0.95
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0147
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of ... Read more
- EPSS Score: %21.35
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025