Latest CVE Feed
-
7.5
HIGHCVE-2003-0555
ImageMagick 5.4.3.x and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a "%x" filename, possibly triggering a format string vulnerability.... Read more
Affected Products : imagemagick- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0580
Buffer overflow in uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier allows the uvadm user to execute arbitrary code via a long -uv.install command line argument.... Read more
Affected Products : u2_universe- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2003-0567
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.... Read more
- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0557
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.... Read more
Affected Products : storefront- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-1263
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as s... Read more
Affected Products : metamail- Published: Aug. 15, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1088
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary web script or HTML via the method parameter.... Read more
Affected Products : zorum- Published: Aug. 11, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0455
The imagemagick libmagick library 5.5 and earlier creates temporary files insecurely, which allows local users to create or overwrite arbitrary files.... Read more
Affected Products : libmagick_library- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0505
Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.... Read more
Affected Products : netmeeting- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0506
Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.... Read more
Affected Products : netmeeting- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0474
Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.... Read more
Affected Products : iweb_server- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0510
Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.... Read more
Affected Products : ezbounce- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0452
Buffer overflows in osh before 1.7-11 allow local users to execute arbitrary code and bypass shell restrictions via (1) long environment variables or (2) long "file redirections."... Read more
Affected Products : osh- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0509
SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.... Read more
Affected Products : eshop- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0489
tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.... Read more
Affected Products : tcptraceroute- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0487
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl ... Read more
Affected Products : kerio_mailserver- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0454
Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.... Read more
Affected Products : xgalaga- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0498
Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.... Read more
Affected Products : cache_database- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0493
Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.... Read more
Affected Products : snitz_forums_2000- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0453
traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overfl... Read more
Affected Products : traceroute-nanog- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0449
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or... Read more
Affected Products : database- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025