Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2003-0111

    The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in ... Read more

    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0163

    decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a... Read more

    Affected Products : gaim-encryption
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0171

    DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.... Read more

    Affected Products : mac_os_x mac_os_x_server
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0201

    Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.... Read more

    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0173

    xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.... Read more

    Affected Products : irix xfsdump
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0204

    KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.... Read more

    Affected Products : kde
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0209

    Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.... Read more

    Affected Products : snort smoothwall
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-0208

    Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.... Read more

    Affected Products : flash
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0211

    Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.... Read more

    Affected Products : xinetd
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0110

    The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malform... Read more

    Affected Products : isa_server proxy_server
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-1072

    Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).... Read more

    Affected Products : solaris sunos
    • Published: Apr. 28, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1070

    Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).... Read more

    Affected Products : solaris sunos
    • Published: Apr. 28, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1465

    SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.... Read more

    Affected Products : b2
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1471

    The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-mi... Read more

    Affected Products : evolution
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2002-1484

    DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a... Read more

    Affected Products : db4web
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1478

    Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.... Read more

    Affected Products : cacti
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1477

    graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.... Read more

    Affected Products : cacti
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1474

    Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service.... Read more

    Affected Products : tru64
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2002-1464

    Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.... Read more

    Affected Products : b2
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1481

    savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.... Read more

    Affected Products : phpgb
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 293192 Results