Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2003-0318

    Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.... Read more

    Affected Products : php-nuke
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0325

    Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.... Read more

    Affected Products : maelstrom
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1460

    L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.... Read more

    Affected Products : l-forum
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0330

    Buffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.... Read more

    Affected Products : maelstrom
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0361

    gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unauthorized remote attackers to connect to rgpsp.... Read more

    Affected Products : debian_linux
    • Published: Jun. 09, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-1068

    Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4659277, a different vulnerability than CVE-2003-1082.... Read more

    Affected Products : solaris sunos
    • Published: Jun. 06, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1069

    The Telnet daemon (in.telnetd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (CPU consumption by infinite loop).... Read more

    Affected Products : solaris sunos
    • Published: Jun. 03, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1206

    Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir.... Read more

    Affected Products : crob_ftp_server
    • Published: Jun. 03, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0235

    Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.... Read more

    Affected Products : icq
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0259

    Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.... Read more

    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0262

    leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.... Read more

    Affected Products : leksbot
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0269

    Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.... Read more

    Affected Products : youbin
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0272

    admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.... Read more

    Affected Products : miniportal
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0237

    The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.... Read more

    Affected Products : icq
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2003-0265

    Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.... Read more

    Affected Products : sap_db
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0228

    Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an ... Read more

    Affected Products : windows_media_player
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0261

    fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges.... Read more

    Affected Products : fuzz
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0243

    Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.... Read more

    Affected Products : happymall
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2003-0273

    Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.... Read more

    Affected Products : request_tracker
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0267

    ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.... Read more

    Affected Products : slwebmail
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 294690 Results