Latest CVE Feed
-
4.6
MEDIUMCVE-2003-1095
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access witho... Read more
Affected Products : weblogic_server- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0124
man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in t... Read more
Affected Products : man- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0067
The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, whi... Read more
Affected Products : aterm- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0126
The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.... Read more
Affected Products : routefinder_550_vpn- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1203
Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.... Read more
Affected Products : mambo_site_server- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0077
The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when th... Read more
Affected Products : hanterm-xf- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0020
Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.... Read more
Affected Products : http_server- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0123
Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.... Read more
- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0053
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an e... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1337
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0009
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0052
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0055
Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.... Read more
Affected Products : quicktime_darwin_mp3_broadcaster- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0050
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0033
Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.... Read more
Affected Products : snort- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0103
Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.... Read more
Affected Products : 6210_handset- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0051
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0107
Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.... Read more
Affected Products : zlib- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0108
isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.... Read more
Affected Products : tcpdump- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025