Latest CVE Feed
-
5.0
MEDIUMCVE-2003-0206
gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.... Read more
Affected Products : gkrellm_newsticker- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0205
gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.... Read more
Affected Products : gkrellm_newsticker- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2002-1563
stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions that cause an inconsistency in the child counter.... Read more
Affected Products : stunnel- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0214
run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : mime-support- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0219
Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.... Read more
Affected Products : personal_firewall_2- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0116
Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and t... Read more
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1562
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.... Read more
Affected Products : thttpd- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0220
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.... Read more
Affected Products : personal_firewall_2- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0112
Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.... Read more
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0118
SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.as... Read more
Affected Products : biztalk_server- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0084
mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.... Read more
Affected Products : mod_auth_any- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2003-0216
Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.... Read more
Affected Products : catos- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0190
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.... Read more
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0115
Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a diff... Read more
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0218
Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.... Read more
Affected Products : monkey- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0213
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.... Read more
Affected Products : pptp_server- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0215
SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.... Read more
Affected Products : bttlxeforum- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2003-0222
Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.... Read more
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1146
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.... Read more
Affected Products : easy_php_photo_album- Published: May. 11, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0334
BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.... Read more
Affected Products : bitchx- Published: May. 10, 2003
- Modified: Apr. 03, 2025