Latest CVE Feed
-
7.2
HIGHCVE-2002-1540
The client for Symantec Norton AntiVirus Corporate Edition 7.5.x before 7.5.1 Build 62 and 7.6.x before 7.6.1 Build 35a runs winhlp32 with raised privileges, which allows local users to gain privileges by using certain features of winhlp32.... Read more
Affected Products : norton_antivirus- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1547
Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability th... Read more
Affected Products : netscreen_screenos- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0146
Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows,... Read more
Affected Products : netpbm- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1553
Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist.... Read more
Affected Products : optical_networking_systems_software- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1541
BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).... Read more
Affected Products : badblue- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0080
The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.... Read more
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1539
Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.... Read more
Affected Products : mdaemon- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0145
Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.... Read more
Affected Products : tcpdump- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0144
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) ... Read more
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-1074
Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.... Read more
Affected Products : solaris- Published: Mar. 28, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0028
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certa... Read more
- Published: Mar. 25, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0129
Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.... Read more
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0140
Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary co... Read more
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2003-0150
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifyin... Read more
Affected Products : mysql- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0010
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large ar... Read more
Affected Products : windows_2000 windows_xp windows_98 windows_nt windows_98se windows_me windows_2000_terminal_services- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0130
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded imag... Read more
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0138
Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.... Read more
Affected Products : kerberos- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0156
Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.... Read more
Affected Products : lxr- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0139
Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste ... Read more
Affected Products : kerberos- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0128
The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggerin... Read more
- Published: Mar. 24, 2003
- Modified: Apr. 03, 2025