Latest CVE Feed
-
7.2
HIGHCVE-2003-0089
Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.... Read more
Affected Products : hp-ux- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0937
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which lea... Read more
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0795
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to th... Read more
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0812
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated usin... Read more
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0962
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.... Read more
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0950
PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (system time) name of the directory used to store the file, and directly reque... Read more
Affected Products : peopletools- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0942
Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a long Name parameter to waadmin.wa.... Read more
Affected Products : sap_db- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0821
Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.... Read more
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0946
Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the email address ... Read more
Affected Products : clamav- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0941
web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.... Read more
Affected Products : sap_db- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0975
Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.... Read more
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0629
Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTTP request to IScript.... Read more
Affected Products : peopletools- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0628
PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI) files via an HTTP request with an invalid value.... Read more
Affected Products : peopletools- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0940
Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.... Read more
Affected Products : sap_db- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0976
NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount file systems when XNFS should deny the host.... Read more
Affected Products : netware- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0955
OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2... Read more
Affected Products : openbsd- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0951
Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.... Read more
Affected Products : hp-ux- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0932
Buffer overflow in omega-rpg 0.90 allows local users to execute arbitrary code via a long (1) command line or (2) environment variable.... Read more
Affected Products : omega-rpg- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0820
Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2003-0859
The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.... Read more
Affected Products : enterprise_linux glibc linux_advanced_workstation propack zebra quagga_routing_software_suite ia64- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025