Latest CVE Feed
-
7.5
HIGHCVE-2003-0751
SQL injection vulnerability in pass_done.php for PY-Membres 4.2 and earlier allows remote attackers to execute arbitrary SQL queries via the email parameter.... Read more
Affected Products : py-membres- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0733
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) ... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0754
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.... Read more
Affected Products : newsphp- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0752
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.... Read more
Affected Products : attilaphp- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0746
Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs, as triggered by attempted exploits against the vulnerab... Read more
Affected Products : openview- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0747
wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~lang... Read more
Affected Products : internet_transaction_server- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0753
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.... Read more
Affected Products : newsphp- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0749
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.... Read more
Affected Products : internet_transaction_server- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0730
Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0661
The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0708
Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.... Read more
Affected Products : linuxnode- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0737
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0665
Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.... Read more
Affected Products : access- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0739
VMware Workstation 4.0.1 for Linux, build 5289 and earlier, allows local users to delete arbitrary files via a symlink attack.... Read more
Affected Products : workstation- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0750
secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.... Read more
Affected Products : py-membres- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0689
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.... Read more
Affected Products : enterprise_linux- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0707
Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.... Read more
Affected Products : linuxnode- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0748
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filenam... Read more
Affected Products : internet_transaction_server- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0729
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.... Read more
Affected Products : tftpdnt- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0735
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025