Latest CVE Feed
-
7.5
HIGHCVE-2003-0054
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log fil... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0055
Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.... Read more
Affected Products : quicktime_darwin_mp3_broadcaster- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0103
Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.... Read more
Affected Products : 6210_handset- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-1077
Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).... Read more
Affected Products : solaris- Published: Mar. 05, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0842
Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" r... Read more
Affected Products : application_server- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0068
The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious ... Read more
Affected Products : eterm- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0071
The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.... Read more
Affected Products : x11r6- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1511
The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1472
Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0097
Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).... Read more
Affected Products : php- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0024
The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.... Read more
Affected Products : aterm- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0070
VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal,... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0049
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0066
The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious s... Read more
Affected Products : rxvt- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0100
Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.... Read more
Affected Products : ios- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1510
xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0099
Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.... Read more
Affected Products : apcupsd- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0079
The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.... Read more
Affected Products : hanterm-xf- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0087
Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0098
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025