Latest CVE Feed
-
5.0
MEDIUMCVE-2003-0744
The fetchnews NNTP client in leafnode 1.9.3 to 1.9.41 allows remote attackers to cause a denial of service (process hang and termination) via certain malformed Usenet news articles that cause fetchnews to hang while waiting for input.... Read more
Affected Products : leafnode- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0725
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0756
Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.... Read more
Affected Products : sitebuilder- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0731
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and ... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0752
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.... Read more
Affected Products : attilaphp- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0737
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0664
Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0734
Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictions and log onto the system.... Read more
Affected Products : pam_ldap- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0736
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id ... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0726
RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated u... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0733
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) ... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-1062
Unknown vulnerability in the sysinfo system call for Solaris for SPARC 2.6 through 9, and Solaris for x86 2.6, 7, and 8, allows local users to read kernel memory.... Read more
- Published: Oct. 15, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-1061
Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.... Read more
- Published: Oct. 14, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2003-0791
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.... Read more
- Published: Oct. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0785
ipmasq before 3.5.12, in certain configurations, may forward packets to the external interface even if the packets are not associated with an established connection, which could allow remote attackers to bypass intended filtering.... Read more
Affected Products : ipmasq- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0697
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.... Read more
Affected Products : aix- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0681
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.... Read more
Affected Products : aix hp-ux mac_os_x mac_os_x_server netbsd openbsd sendmail linux turbolinux_server turbolinux_workstation +4 more products- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0826
lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer ove... Read more
Affected Products : lsh- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0695
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vu... Read more
Affected Products : openssh- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0682
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.... Read more
Affected Products : openssh- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025