Latest CVE Feed
-
5.0
MEDIUMCVE-2002-1348
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.... Read more
Affected Products : w3m- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2002-1508
slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.... Read more
Affected Products : openldap- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1405
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1160
The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentia... Read more
Affected Products : linux- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0058
MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0004
Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.... Read more
Affected Products : windows_xp- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1326
Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0046
AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.... Read more
Affected Products : absolutetelnet- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1079
Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allo... Read more
- Published: Feb. 18, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-1080
Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.... Read more
- Published: Feb. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0017
Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.... Read more
Affected Products : http_server- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0027
Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.... Read more
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0016
Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.... Read more
Affected Products : http_server- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2003-0036
ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".... Read more
Affected Products : ml85p- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0015
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-pr... Read more
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1252
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the Sim... Read more
Affected Products : peopletools- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0043
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0044
Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0038
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.... Read more
Affected Products : mailman- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0045
Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025