Latest CVE Feed
-
10.0
HIGHCVE-2003-0509
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.... Read more
Affected Products : eshop- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0452
Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."... Read more
Affected Products : osh- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0477
wzdftpd 0.1rc4 and earlier allows remote attackers to cause a denial of service (crash) via a PORT command without an argument.... Read more
Affected Products : wzdftpd- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0490
The installation of Dantz Retrospect Client 5.0.540 on MacOS X 10.2.6, and possibly other versions, creates critical directories and files with world-writable permissions, which allows local users to gain privileges as other users by replacing programs wi... Read more
Affected Products : retrospect_client- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0482
TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.... Read more
Affected Products : tutos- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0481
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.... Read more
Affected Products : tutos- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0497
Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.... Read more
Affected Products : cache_database- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0488
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.... Read more
Affected Products : kerio_mailserver- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1205
Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name.... Read more
Affected Products : crob_ftp_server- Published: Aug. 06, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0643
Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).... Read more
Affected Products : linux_kernel- Published: Jul. 25, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0431
The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.... Read more
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0445
Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI.... Read more
Affected Products : webfs- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0435
Buffer overflow in net_swapscore for typespeed 0.4.1 and earlier allows remote attackers to execute arbitrary code.... Read more
Affected Products : typespeed- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0366
lyskom-server 2.0.7 and earlier allows unauthenticated users to cause a denial of service (CPU consumption) via a large query.... Read more
Affected Products : lyskom-server- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0430
The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.... Read more
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-1409
dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.... Read more
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0434
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.... Read more
Affected Products : enterprise_linux acrobat linux xpdf linux_advanced_workstation mandrake_linux mandrake_linux_corporate_server- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0348
A certain Microsoft Windows Media Player 9 Series ActiveX control allows remote attackers to view and manipulate the Media Library on the local system via HTML script.... Read more
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0428
Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.... Read more
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0251
ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.... Read more
Affected Products : ypserv_nis_server- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025