Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2003-0210

    Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.... Read more

    Affected Products : secure_access_control_server
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0206

    gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.... Read more

    Affected Products : gkrellm_newsticker
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0219

    Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.... Read more

    Affected Products : personal_firewall_2
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0212

    handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of ... Read more

    Affected Products : rinetd
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0113

    Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.... Read more

    Affected Products : internet_explorer ie
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0116

    Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and t... Read more

    Affected Products : internet_explorer ie
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1562

    Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.... Read more

    Affected Products : thttpd
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0233

    Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.... Read more

    Affected Products : internet_explorer ie
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0118

    SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.as... Read more

    Affected Products : biztalk_server
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0218

    Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.... Read more

    Affected Products : monkey
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0084

    mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.... Read more

    Affected Products : mod_auth_any
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 9.3

    HIGH
    CVE-2003-0216

    Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.... Read more

    Affected Products : catos
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0190

    OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.... Read more

    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0114

    The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.... Read more

    Affected Products : internet_explorer ie
    • Published: May. 12, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-1146

    Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.... Read more

    Affected Products : easy_php_photo_album
    • Published: May. 11, 2003
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-0334

    BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.... Read more

    Affected Products : bitchx
    • Published: May. 10, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0196

    Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.... Read more

    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0163

    decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a... Read more

    Affected Products : gaim-encryption
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-0208

    Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.... Read more

    Affected Products : flash
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0209

    Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.... Read more

    Affected Products : snort smoothwall
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 293513 Results