Latest CVE Feed
-
7.2
HIGHCVE-2003-0019
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.... Read more
Affected Products : linux- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0048
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.... Read more
Affected Products : putty- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0076
Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1348
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.... Read more
Affected Products : w3m- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0074
Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.... Read more
Affected Products : plptools- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2003-0018
Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2002-1508
slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.... Read more
Affected Products : openldap- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0075
Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.... Read more
Affected Products : bladeenc- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0040
SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0004
Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.... Read more
Affected Products : windows_xp- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1079
Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allo... Read more
- Published: Feb. 18, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-1080
Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.... Read more
- Published: Feb. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0043
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0039
ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not re... Read more
Affected Products : dhcpd- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0002
Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.... Read more
Affected Products : content_management_server- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0007
Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certif... Read more
Affected Products : outlook- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0003
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter informat... Read more
Affected Products : windows_2000 windows_xp windows_nt windows_2000_terminal_services windows_2000_terminal_services- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0035
Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.... Read more
Affected Products : escputil- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0044
Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0015
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-pr... Read more
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025