Latest CVE Feed
-
7.5
HIGHCVE-2002-1570
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variabl... Read more
Affected Products : ucd-snmp- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0901
Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.... Read more
Affected Products : postgresql- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1184
Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."... Read more
Affected Products : thwboard- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1142
Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.... Read more
Affected Products : niprint_lpd-lpr_print_server- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0871
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2003-0855
Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0895
Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0881
Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1185
Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.... Read more
Affected Products : thwboard- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0876
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than in... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1196
SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.... Read more
Affected Products : vieboard- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0789
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.... Read more
Affected Products : http_server- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1188
Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.... Read more
Affected Products : unichat- Published: Nov. 02, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1187
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.... Read more
Affected Products : phpkit- Published: Nov. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1159
Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.... Read more
Affected Products : plug_and_play_web_server_proxy- Published: Oct. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1160
FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).... Read more
Affected Products : flexwatch_network_video_server- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1143
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.... Read more
Affected Products : serioussam- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1197
Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.... Read more
Affected Products : ledforums- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1194
Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.... Read more
Affected Products : booby- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1191
chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.... Read more
Affected Products : e107- Published: Oct. 29, 2003
- Modified: Apr. 03, 2025