Latest CVE Feed
-
7.5
HIGHCVE-2003-0378
The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.... Read more
Affected Products : mac_os_x- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0275
SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : yabb- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0283
Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.... Read more
Affected Products : phorum- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0294
autohtml.php in php-proxima 6.0 and earlier allows remote attackers to read arbitrary files via the name parameter in a modload operation.... Read more
Affected Products : php-proxima- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0301
The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.... Read more
Affected Products : outlook_express- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0284
Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.... Read more
Affected Products : acrobat- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0370
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.... Read more
- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0377
SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variabl... Read more
Affected Products : iisprotect- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2003-0246
The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.... Read more
Affected Products : linux_kernel- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0247
Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").... Read more
Affected Products : linux- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0289
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.... Read more
Affected Products : cdrecord- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2003-0270
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing whe... Read more
Affected Products : 802.11n- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0313
Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request.... Read more
Affected Products : snowblind_web_server- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0281
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_... Read more
Affected Products : firebird- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0288
Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.... Read more
Affected Products : ip_messenger- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0312
Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.... Read more
Affected Products : snowblind_web_server- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0295
Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.... Read more
Affected Products : vbulletin- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0299
The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer ove... Read more
- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0286
SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.... Read more
Affected Products : snitz_forums_2000- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0296
The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.... Read more
Affected Products : evolution- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025