Latest CVE Feed
-
7.5
HIGHCVE-2003-0037
Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.... Read more
Affected Products : noffle- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0042
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0017
Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.... Read more
Affected Products : http_server- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0016
Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.... Read more
Affected Products : http_server- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0015
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-pr... Read more
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0027
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.... Read more
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2003-0036
ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".... Read more
Affected Products : ml85p- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0034
Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.... Read more
Affected Products : mtink- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0038
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.... Read more
Affected Products : mailman- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0007
Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certif... Read more
Affected Products : outlook- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0035
Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.... Read more
Affected Products : escputil- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0003
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter informat... Read more
Affected Products : windows_2000 windows_xp windows_nt windows_2000_terminal_services windows_2000_terminal_services- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1252
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the Sim... Read more
Affected Products : peopletools- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1090
Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.... Read more
Affected Products : absolutetelnet- Published: Feb. 06, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1075
Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.... Read more
- Published: Jan. 27, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0032
Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.... Read more
Affected Products : libmcrypt- Published: Jan. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0001
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.... Read more
- Published: Jan. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1395
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via imm... Read more
Affected Products : internet_message- Published: Jan. 17, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1402
Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : postgresql- Published: Jan. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1397
Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow... Read more
Affected Products : postgresql- Published: Jan. 17, 2003
- Modified: Apr. 03, 2025