Latest CVE Feed
-
7.5
HIGHCVE-2002-1469
scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environmen... Read more
Affected Products : scponly- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1476
Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 element... Read more
Affected Products : netbsd- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1479
Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.... Read more
Affected Products : cacti- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1054
mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.... Read more
Affected Products : mod_access_referer- Published: Apr. 16, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-1426
HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow.... Read more
Affected Products : procurve_switch_4000m- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1410
Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.... Read more
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1415
Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests.... Read more
Affected Products : webeasymail- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0169
hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.... Read more
Affected Products : instant_toptools- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1411
Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.... Read more
Affected Products : photo_gallery_system- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0197
Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).... Read more
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1417
Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot), which... Read more
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1412
Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script.... Read more
Affected Products : gallery- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1437
Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.... Read more
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1442
The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then us... Read more
Affected Products : toolbar- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0203
Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.... Read more
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1433
Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.... Read more
Affected Products : kerio_mailserver- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1440
The Gateway GS-400 server has a default root password of "0001n" that can not be changed via the administrative interface, which can allow attackers to gain root privileges.... Read more
Affected Products : gs-400- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1430
Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters.... Read more
Affected Products : sympoll- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1443
The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.... Read more
Affected Products : toolbar- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1418
Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (ABEND) via a long module name.... Read more
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025