Latest CVE Feed
-
7.5
HIGHCVE-2003-1193
Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL c... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1570
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variabl... Read more
Affected Products : ucd-snmp- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2003-0855
Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0871
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0895
Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0881
Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1184
Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."... Read more
Affected Products : thwboard- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1142
Help in NIPrint LPD-LPR Print Server 4.10 and earlier executes Windows Explorer with SYSTEM privileges, which allows local users to gain privileges.... Read more
Affected Products : niprint_lpd-lpr_print_server- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1182
Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.... Read more
Affected Products : mpm_guestbook- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0882
Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0877
Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0880
Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2003-0899
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences... Read more
Affected Products : thttpd- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0883
The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0878
slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1187
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.... Read more
Affected Products : phpkit- Published: Nov. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1188
Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.... Read more
Affected Products : unichat- Published: Nov. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1159
Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.... Read more
Affected Products : plug_and_play_web_server_proxy- Published: Oct. 31, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1194
Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.... Read more
Affected Products : booby- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1143
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.... Read more
Affected Products : serioussam- Published: Oct. 30, 2003
- Modified: Apr. 03, 2025