Latest CVE Feed
-
7.5
HIGHCVE-2003-0845
Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL state... Read more
Affected Products : jboss- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0839
Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.... Read more
Affected Products : windows_2003_server- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0870
Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.... Read more
Affected Products : opera_browser- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0712
Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.... Read more
Affected Products : exchange_server- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0850
The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0813
A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread ... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0660
The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0847
SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.... Read more
Affected Products : suse_linux- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0897
"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications.... Read more
Affected Products : windows_xp- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0861
Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.... Read more
Affected Products : php- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0711
Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0840
Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.... Read more
Affected Products : hp-ux- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0875
Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.... Read more
Affected Products : openslp- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0853
An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0792
Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.... Read more
Affected Products : fetchmail- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0854
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2003-0844
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an... Read more
Affected Products : mod_gzip- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0836
Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary code via a LOAD command.... Read more
Affected Products : db2_universal_database- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0809
Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.... Read more
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0864
Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.... Read more
Affected Products : ircnet_ircd- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025