Latest CVE Feed
-
4.4
MEDIUMCVE-2003-0373
Multiple buffer overflows in libnasl in Nessus before 2.0.6 allow local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code via (1) a long proto argument to the scanner_add_port function, (2) a ... Read more
Affected Products : nessus- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1155
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.... Read more
Affected Products : linux- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0291
3com OfficeConnect Remote 812 ADSL Router 1.1.7 does not properly clear memory from DHCP responses, which allows remote attackers to identify the contents of previous HTTP requests by sniffing DHCP packets.... Read more
Affected Products : 3cp4144- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0420
Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.... Read more
Affected Products : mac_os_x_server- Published: Jun. 13, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0362
Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.... Read more
Affected Products : debian_linux- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0240
The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).... Read more
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0330
Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.... Read more
Affected Products : maelstrom- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0223
Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.... Read more
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1456
Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.... Read more
Affected Products : mirc- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1460
L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.... Read more
Affected Products : l-forum- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0329
CesarFTP 0.99g stores user names and passwords in plaintext in the settings.ini file, which could allow local users to gain privileges.... Read more
Affected Products : cesarftp- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0303
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.... Read more
Affected Products : oneorzero_helpdesk- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0304
one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.... Read more
Affected Products : oneorzero_helpdesk- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1564
Internet Explorer 5.5 and 6.0 allows remote attackers to steal potentially sensitive information from cookies via a cookie that contains script which is executed when a page is loaded, aka the "Script within Cookies Reading Cookies" vulnerability.... Read more
Affected Products : internet_explorer- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0305
The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.... Read more
Affected Products : ios- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0357
Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.... Read more
Affected Products : ethereal- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1457
SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.... Read more
Affected Products : l-forum- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0224
Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overr... Read more
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0322
Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).... Read more
Affected Products : bitchx- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1463
Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers t... Read more
- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025