Latest CVE Feed
-
10.0
HIGHCVE-2003-0409
Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.... Read more
Affected Products : webweaver- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0404
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login ... Read more
- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0411
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.... Read more
- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0413
Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP r... Read more
Affected Products : one_application_server- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0414
The installation of Sun ONE Application Server 7.0 for Windows 2000/XP creates a statefile with world-readable permissions, which allows local users to gain privileges by reading a plaintext password in the statefile.... Read more
Affected Products : one_application_server- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0403
Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.... Read more
- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0417
Directory traversal vulnerability in Son hServer 0.2 allows remote attackers to read arbitrary files via ".|." (modified dot-dot) sequences.... Read more
Affected Products : son_hserver- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1067
Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.... Read more
- Published: Jun. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1086
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the ... Read more
- Published: Jun. 17, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0289
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.... Read more
Affected Products : cdrecord- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0300
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.... Read more
- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0314
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence.... Read more
Affected Products : snowblind_web_server- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0371
Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP banner.... Read more
Affected Products : prishtina_ftp- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0316
Venturi Client before 2.2, as used in certain Fourelle and Venturi Wireless products, can be used as an open proxy for various protocols, including an open relay for SMTP, which allows it to be abused by spammers.... Read more
Affected Products : venturi_client- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0277
Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.... Read more
Affected Products : happymall- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0374
Multiple unknown vulnerabilities in Nessus before 2.0.6, in libnessus and possibly libnasl, a different set of vulnerabilities than those identified by CVE-2003-0372 and CVE-2003-0373, aka "similar issues in other nasl functions as well as in libnessus."... Read more
Affected Products : nessus- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0278
Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.... Read more
Affected Products : happymall- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0302
The IMAP Client for Eudora 5.2.1 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.... Read more
Affected Products : eudora- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0285
IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail rel... Read more
Affected Products : aix- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2003-0246
The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.... Read more
Affected Products : linux_kernel- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025