Latest CVE Feed
-
9.0
HIGHCVE-2003-0096
Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0064
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which c... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0024
The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.... Read more
Affected Products : aterm- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0100
Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.... Read more
Affected Products : ios- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1510
xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0049
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0066
The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious s... Read more
Affected Products : rxvt- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0097
Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).... Read more
Affected Products : php- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0070
VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal,... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0022
The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.... Read more
Affected Products : rxvt- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0101
miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a ses... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0063
The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the... Read more
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1078
The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.... Read more
- Published: Feb. 28, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0047
SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0073
Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.... Read more
Affected Products : mysql- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0041
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0057
Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connectin... Read more
Affected Products : hypermail- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0056
Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.... Read more
Affected Products : slocate- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0669
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force authentication of incoming calls, which does not notify th... Read more
Affected Products : xpressa- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0036
Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value.... Read more
Affected Products : kerberos_5- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025