Latest CVE Feed
-
6.8
MEDIUMCVE-2003-1199
Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.... Read more
Affected Products : myproxy- Published: Mar. 11, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1770
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.... Read more
Affected Products : cpanel- Published: Mar. 11, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1769
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.... Read more
Affected Products : cpanel- Published: Mar. 11, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1359
Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.... Read more
- Published: Mar. 04, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0129
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in the what parameter.... Read more
Affected Products : phpmyadmin- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0083
Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-200... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0010
Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.... Read more
Affected Products : linux_kernel- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0096
Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.... Read more
Affected Products : mod_python- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0084
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a differ... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0132
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[languag... Read more
Affected Products : ezcontents- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1575
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, BCC, and other header fields in the generated email messa... Read more
Affected Products : cgiemail- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0441
Multiple buffer overflows in Orville Write (orville-write) 2.53 and earlier allow local users to gain privileges.... Read more
Affected Products : orville-write- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0987
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.... Read more
Affected Products : http_server- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2003-0825
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbit... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0009
Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.... Read more
Affected Products : apache-ssl- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0099
mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended ac... Read more
Affected Products : freebsd- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0080
The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data.... Read more
Affected Products : util-linux- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0127
Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.... Read more
Affected Products : phpgedview- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0003
Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."... Read more
Affected Products : linux_kernel- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-0089
Buffer overflow in TruBlueEnvironment in Mac OS X 10.3.x and 10.2.x allows local users to gain privileges via a long environment variable.... Read more
- Published: Mar. 03, 2004
- Modified: Apr. 03, 2025