Latest CVE Feed
-
4.6
MEDIUMCVE-2003-0449
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or... Read more
Affected Products : database- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0453
traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overfl... Read more
Affected Products : traceroute-nanog- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0490
The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs wi... Read more
Affected Products : retrospect_client- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2003-0499
Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.... Read more
Affected Products : mantis- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0497
Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.... Read more
Affected Products : cache_database- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0508
Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.... Read more
Affected Products : acrobat_reader- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0483
Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter to member.php or (2) the action parameter to buddy.php.... Read more
Affected Products : xmb- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0494
password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.... Read more
Affected Products : snitz_forums_2000- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0473
Unknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.... Read more
Affected Products : irix- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0503
Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument.... Read more
Affected Products : windows_2000- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0469
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 ... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_98 windows_nt windows_98se windows_me- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0485
Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.... Read more
Affected Products : 4gl_compiler- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0491
The Tutorials 2.0 module in XOOPS and E-XOOPS allows remote attackers to execute arbitrary code by uploading a PHP file without a MIME image type, then directly accessing the uploaded file.... Read more
Affected Products : tutorials- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0475
Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.... Read more
Affected Products : iweb_server- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0486
SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.... Read more
Affected Products : phpbb- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0504
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module.... Read more
Affected Products : phpgroupware- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0484
Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.... Read more
Affected Products : phpbb- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0470
Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.... Read more
Affected Products : security_check- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0501
The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.... Read more
Affected Products : linux_kernel- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0477
wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.... Read more
Affected Products : wzdftpd- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025