Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2003-0356

    Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync,... Read more

    Affected Products : ethereal
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0227

    The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Ser... Read more

    Affected Products : windows_2000 windows_nt
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0194

    tcpdump does not properly drop privileges to the pcap user when starting up.... Read more

    Affected Products : linux tcpdump
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0306

    Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.... Read more

    Affected Products : windows_xp
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0226

    Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.... Read more

    Affected Products : internet_information_services iis
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0330

    Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.... Read more

    Affected Products : maelstrom
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0224

    Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overr... Read more

    Affected Products : internet_information_services iis
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0322

    Integer overflow in BitchX IRC client 1.0-0c19 and earlier allows remote malicious IRC servers to cause a denial of service (crash).... Read more

    Affected Products : bitchx
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0321

    Multiple buffer overflows in BitchX IRC client 1.0-0c19 and earlier allow remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long hostnames, nicknames, or channel names, which are not properly handled... Read more

    Affected Products : bitchx
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0324

    Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that are not properly handled by the (1) userhost_cmd_returned function, or (2)... Read more

    Affected Products : epic4
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0305

    The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.... Read more

    Affected Products : ios
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.6

    HIGH
    CVE-2003-0332

    The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats exte... Read more

    Affected Products : badblue
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1462

    details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.... Read more

    Affected Products : php-affiliate
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1454

    MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.... Read more

    Affected Products : mywebserver
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1458

    Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.... Read more

    Affected Products : l-forum
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0331

    SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page.... Read more

    Affected Products : ttforum
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1068

    Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.... Read more

    Affected Products : solaris sunos
    • Published: Jun. 06, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1206

    Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir.... Read more

    Affected Products : crob_ftp_server
    • Published: Jun. 03, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1069

    The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (CPU consumption by infinite loop).... Read more

    Affected Products : solaris sunos
    • Published: Jun. 03, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0274

    Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.... Read more

    Affected Products : listproc
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 293781 Results