Latest CVE Feed
-
7.5
HIGHCVE-2003-0743
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL charac... Read more
Affected Products : exim- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0707
Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.... Read more
Affected Products : linuxnode- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0729
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.... Read more
Affected Products : tftpdnt- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0658
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0735
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0630
Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line arguments, as demonstrated with the -osa_rom argument.... Read more
Affected Products : atari800- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0689
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.... Read more
Affected Products : enterprise_linux- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0748
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filenam... Read more
Affected Products : internet_transaction_server- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0702
Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server ... Read more
Affected Products : realsecure_server_sensor- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0750
secure.php in PY-Membres 4.2 and earlier allows remote attackers to bypass authentication by setting the adminpy parameter.... Read more
Affected Products : py-membres- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0752
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.... Read more
Affected Products : attilaphp- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0688
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Se... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0733
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) ... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0749
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.... Read more
Affected Products : internet_transaction_server- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0740
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.... Read more
Affected Products : stunnel- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0746
Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs, as triggered by attempted exploits against the vulnerab... Read more
Affected Products : openview- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0724
ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.... Read more
Affected Products : tru64- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0747
wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~lang... Read more
Affected Products : internet_transaction_server- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2003-0738
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0666
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.... Read more
Affected Products : wordperfect_converter- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025