Latest CVE Feed
-
5.0
MEDIUMCVE-2002-1562
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.... Read more
Affected Products : thttpd- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0113
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.... Read more
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0210
Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.... Read more
Affected Products : secure_access_control_server- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0205
gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.... Read more
Affected Products : gkrellm_newsticker- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0116
Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and t... Read more
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0214
run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : mime-support- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0219
Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.... Read more
Affected Products : personal_firewall_2- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0212
handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of ... Read more
Affected Products : rinetd- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0206
gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.... Read more
Affected Products : gkrellm_newsticker- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1146
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.... Read more
Affected Products : easy_php_photo_album- Published: May. 11, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0334
BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.... Read more
Affected Products : bitchx- Published: May. 10, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0136
psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.... Read more
Affected Products : lprng- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0173
xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.... Read more
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0110
The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malform... Read more
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0204
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.... Read more
Affected Products : kde- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0196
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.... Read more
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0111
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in ... Read more
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0163
decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a... Read more
Affected Products : gaim-encryption- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0207
ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.... Read more
Affected Products : gs-common- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0201
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.... Read more
- Published: May. 05, 2003
- Modified: Apr. 03, 2025