Latest CVE Feed
-
7.5
HIGHCVE-2003-0870
Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.... Read more
Affected Products : opera_browser- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0845
Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL state... Read more
Affected Products : jboss- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1568
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demons... Read more
Affected Products : openssl- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0711
Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0864
Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.... Read more
Affected Products : ircnet_ircd- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0894
Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0872
Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.... Read more
Affected Products : openserver- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0852
Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings in an error message.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0840
Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.... Read more
Affected Products : hp-ux- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0838
Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0875
Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.... Read more
Affected Products : openslp- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0897
"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications.... Read more
Affected Products : windows_xp- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0813
A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread ... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0843
Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in... Read more
Affected Products : mod_gzip- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0794
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading ... Read more
Affected Products : gdm- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0786
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.... Read more
Affected Products : openssh- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0787
The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.... Read more
Affected Products : openssh- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2003-0844
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an... Read more
Affected Products : mod_gzip- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0809
Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0836
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.... Read more
Affected Products : db2_universal_database- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025