Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.8

    MEDIUM
    CVE-2003-0413

    Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP r... Read more

    Affected Products : one_application_server
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0405

    Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in the NEEDS command, or (2) an HTTP Referrer that is processed in the VALID_PATHS command.... Read more

    Affected Products : content_suite storyserver vignette
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0412

    Sun ONE Application Server 7.0 for Windows 2000/XP does not log the complete URI of a long HTTP request, which could allow remote attackers to hide malicious activities.... Read more

    Affected Products : one_application_server
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1067

    Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.... Read more

    Affected Products : solaris sunos
    • Published: Jun. 19, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-1086

    PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the ... Read more

    Affected Products : pmachine_pro pmachine_free
    • Published: Jun. 17, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0289

    Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.... Read more

    Affected Products : cdrecord
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-0375

    Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web script via the "member" parameter.... Read more

    Affected Products : xmb
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-1155

    Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.... Read more

    Affected Products : linux
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2003-0314

    Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence.... Read more

    Affected Products : snowblind_web_server
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0300

    The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.... Read more

    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0316

    Venturi Client before 2.2, as used in certain Fourelle and Venturi Wireless products, can be used as an open proxy for various protocols, including an open relay for SMTP, which allows it to be abused by spammers.... Read more

    Affected Products : venturi_client
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0277

    Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.... Read more

    Affected Products : happymall
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0315

    Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.... Read more

    Affected Products : snowblind_web_server
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0293

    PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.... Read more

    Affected Products : palmos
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0291

    3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.... Read more

    Affected Products : 3cp4144
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0299

    The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer ove... Read more

    Affected Products : mutt balsa
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0288

    Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.... Read more

    Affected Products : ip_messenger
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0295

    Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.... Read more

    Affected Products : vbulletin
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 7.6

    HIGH
    CVE-2003-0270

    The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing whe... Read more

    Affected Products : 802.11n
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0281

    Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_... Read more

    Affected Products : firebird
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 292916 Results