Latest CVE Feed
-
7.5
HIGHCVE-2003-0595
Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference.... Read more
Affected Products : wintango_application_server- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0653
The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote attackers to cause a denial of service (kernel panic or c... Read more
Affected Products : netbsd- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0637
Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.... Read more
Affected Products : ichain- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0635
Unknown vulnerability or vulnerabilities in Novell iChain 2.2 before Support Pack 1, with unknown impact, possibly related to unauthorized access to (1) NCPIP.NLM and (2) JSTCP.NLM.... Read more
Affected Products : ichain- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0604
Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF fil... Read more
Affected Products : windows_media_player- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1063
The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.... Read more
- Published: Aug. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1202
The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.... Read more
Affected Products : omail_webmail- Published: Aug. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0519
Certain versions of Internet Explorer 5 and 6, in certain Windows environments, allow remote attackers to cause a denial of service (freeze) via a URL to C:\aux (MS-DOS device name) and possibly other devices.... Read more
Affected Products : internet_explorer- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0526
Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in... Read more
Affected Products : isa_server- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2003-0524
Qt in Knoppix 3.1 Live CD allows local users to overwrite arbitrary files via a symlink attack on the qt_plugins_3.0rc temporary file in the .qt directory.... Read more
Affected Products : knoppix- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0496
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.... Read more
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0177
SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.... Read more
Affected Products : irix- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0516
cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.... Read more
Affected Products : mgetty- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0581
X Fontserver for Truetype fonts (xfstt) 1.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a (1) FS_QueryXExtents8 or (2) FS_QueryXBitmaps8 packet, and possibly other types of packets, with a large num_ranges ... Read more
Affected Products : xfstt- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
6.9
MEDIUMCVE-2003-0587
Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.... Read more
Affected Products : ultimate_bulletin_board- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1410
Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via... Read more
Affected Products : internet_explorer- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0586
Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.... Read more
Affected Products : estore- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2003-0517
faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.... Read more
Affected Products : mgetty- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0579
uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.... Read more
Affected Products : u2_universe- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0585
SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.... Read more
Affected Products : estore- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025