Latest CVE Feed
-
5.0
MEDIUMCVE-2003-0852
Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0626
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.... Read more
Affected Products : peopletools- Published: Nov. 13, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1141
Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.... Read more
Affected Products : niprint_lpd-lpr_print_server- Published: Nov. 04, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1144
Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.... Read more
Affected Products : liteserve- Published: Nov. 04, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1192
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.... Read more
Affected Products : ia_webmail_server- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1145
Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.... Read more
Affected Products : openautoclassifieds- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1193
Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL c... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0683
NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.... Read more
Affected Products : irix- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1142
Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.... Read more
Affected Products : niprint_lpd-lpr_print_server- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1184
Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."... Read more
Affected Products : thwboard- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0882
Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0877
Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1190
Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe.... Read more
Affected Products : phprecipebook- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1182
Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.... Read more
Affected Products : mpm_guestbook- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0880
Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1185
Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.... Read more
Affected Products : thwboard- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1196
SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.... Read more
Affected Products : vieboard- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0876
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than in... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1570
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variabl... Read more
Affected Products : ucd-snmp- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0901
Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.... Read more
Affected Products : postgresql- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025