Latest CVE Feed
-
7.5
HIGHCVE-2003-0179
Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control... Read more
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0152
Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.... Read more
Affected Products : bonsai- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0082
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (ak... Read more
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0083
Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to ... Read more
Affected Products : http_server- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2003-0141
The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed d... Read more
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0072
The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an arr... Read more
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1528
MsmMask.exe in MondoSearch 4.4 allows remote attackers to obtain the source code of scripts via the mask parameter.... Read more
Affected Products : mondosearch- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0162
Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.... Read more
Affected Products : ecartis- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-0086
The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.... Read more
Affected Products : samba- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0146
Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows,... Read more
Affected Products : netpbm- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0109
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.... Read more
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0147
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of ... Read more
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0080
The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.... Read more
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0144
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) ... Read more
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1557
Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.... Read more
Affected Products : optical_networking_systems_software- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1554
Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.... Read more
Affected Products : optical_networking_systems_software- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1555
Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : optical_networking_systems_software- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1546
BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence.... Read more
Affected Products : webweaver- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1543
Buffer overflow in trek on NetBSD 1.5 through 1.5.3 allows local users to gain privileges via long keyboard input.... Read more
Affected Products : netbsd- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1530
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.... Read more
Affected Products : superscout_email_filter- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025