Latest CVE Feed
-
7.5
HIGHCVE-2003-0075
Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.... Read more
Affected Products : bladeenc- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-1328
The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security V... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0074
Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.... Read more
Affected Products : plptools- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1405
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters... Read more
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0669
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force authentication of incoming calls, which does not notify th... Read more
Affected Products : xpressa- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1079
Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allo... Read more
- Published: Feb. 18, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-1080
Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.... Read more
- Published: Feb. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0039
ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not re... Read more
Affected Products : dhcpd- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0003
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter informat... Read more
Affected Products : windows_2000 windows_xp windows_nt windows_2000_terminal_services windows_2000_terminal_services- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0035
Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.... Read more
Affected Products : escputil- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0007
Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certif... Read more
Affected Products : outlook- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0038
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.... Read more
Affected Products : mailman- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0042
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1252
The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the Sim... Read more
Affected Products : peopletools- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0044
Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2003-0002
Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.... Read more
Affected Products : content_management_server- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0043
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.... Read more
Affected Products : tomcat- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0016
Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.... Read more
Affected Products : http_server- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0017
Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.... Read more
Affected Products : http_server- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0015
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-pr... Read more
- Published: Feb. 07, 2003
- Modified: Apr. 03, 2025