Latest CVE Feed
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0053
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an e... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0052
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0033
Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.... Read more
Affected Products : snort- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0009
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0055
Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.... Read more
Affected Products : quicktime_darwin_mp3_broadcaster- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0054
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log fil... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0051
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0107
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.... Read more
Affected Products : zlib- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0103
Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.... Read more
Affected Products : 6210_handset- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0108
isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.... Read more
Affected Products : tcpdump- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0050
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-1077
Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).... Read more
Affected Products : solaris- Published: Mar. 05, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0088
TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.... Read more
Affected Products : mac_os_x- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0021
The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.... Read more
Affected Products : eterm- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0087
Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0070
VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal,... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1472
Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0024
The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.... Read more
Affected Products : aterm- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0097
Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).... Read more
Affected Products : php- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025