Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2003-0328

    EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect lengt... Read more

    Affected Products : linux epic4
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0355

    Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.... Read more

    Affected Products : safari konqueror_embedded
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0331

    SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.... Read more

    Affected Products : ttforum
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0303

    SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.... Read more

    Affected Products : oneorzero_helpdesk
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0319

    Buffer overflow in the IMAP server (IMAPMax) for SmartMax MailMax 5.0.10.8 and earlier allows remote authenticated users to execute arbitrary code via a long SELECT command.... Read more

    Affected Products : mailmax
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0325

    Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.... Read more

    Affected Products : maelstrom
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0307

    Poster version.two allows remote authenticated users to gain administrative privileges by appending the "|" field separator and an "admin" value into the email address field.... Read more

    Affected Products : poster
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2003-0318

    Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.... Read more

    Affected Products : php-nuke
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0223

    Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.... Read more

    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0226

    Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.... Read more

    Affected Products : internet_information_services iis
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0360

    Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.... Read more

    Affected Products : debian_linux
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0361

    gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.... Read more

    Affected Products : debian_linux
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0324

    Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2)... Read more

    Affected Products : epic4
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0321

    Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled... Read more

    Affected Products : bitchx
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0305

    The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.... Read more

    Affected Products : ios
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.6

    HIGH
    CVE-2003-0332

    The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats exte... Read more

    Affected Products : badblue
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0330

    Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.... Read more

    Affected Products : maelstrom
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1461

    Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.... Read more

    Affected Products : web_shop_manager
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1462

    details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.... Read more

    Affected Products : php-affiliate
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1458

    Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.... Read more

    Affected Products : l-forum
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 293609 Results