Latest CVE Feed
-
10.0
HIGHCVE-2003-0755
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.... Read more
Affected Products : gtkftp- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0745
SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.... Read more
Affected Products : snmpc- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0658
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0630
Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line arguments, as demonstrated with the -osa_rom argument.... Read more
Affected Products : atari800- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0347
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0689
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.... Read more
Affected Products : enterprise_linux- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2003-0738
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2003-0740
Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.... Read more
Affected Products : stunnel- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0666
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.... Read more
Affected Products : wordperfect_converter- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0727
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.... Read more
Affected Products : database_server- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0724
ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.... Read more
Affected Products : tru64- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2003-0728
Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.... Read more
Affected Products : horde- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0757
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.... Read more
Affected Products : firewall-1- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0756
Directory traversal vulnerability in sitebuilder.cgi in SiteBuilder 1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the selectedpage parameter.... Read more
Affected Products : sitebuilder- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0661
The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0730
Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0737
The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library.... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0708
Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.... Read more
Affected Products : linuxnode- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0743
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL charac... Read more
Affected Products : exim- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0736
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id ... Read more
Affected Products : phpwebsite- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025