Latest CVE Feed
-
7.5
HIGHCVE-2003-0787
The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.... Read more
Affected Products : openssh- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0843
Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in... Read more
Affected Products : mod_gzip- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0786
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.... Read more
Affected Products : openssh- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0794
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading ... Read more
Affected Products : gdm- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0872
Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.... Read more
Affected Products : openserver- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0626
psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.... Read more
Affected Products : peopletools- Published: Nov. 13, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1141
Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.... Read more
Affected Products : niprint_lpd-lpr_print_server- Published: Nov. 04, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1144
Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.... Read more
Affected Products : liteserve- Published: Nov. 04, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1192
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.... Read more
Affected Products : ia_webmail_server- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2003-0855
Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1145
Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.... Read more
Affected Products : openautoclassifieds- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0871
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."... Read more
- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0895
Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0881
Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0683
NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.... Read more
Affected Products : irix- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0789
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.... Read more
Affected Products : http_server- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0883
The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0880
Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.... Read more
Affected Products : mac_os_x- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2003-0899
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences... Read more
Affected Products : thttpd- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-1182
Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.... Read more
Affected Products : mpm_guestbook- Published: Nov. 03, 2003
- Modified: Apr. 03, 2025