CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2003-0140

    Last Modified: 16 Apr 2026

    Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.

    Published: 20 Mar 2003
    5
    Medium

    CVE-2003-0130

    Last Modified: 16 Apr 2026

    The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.

    Published: 19 Mar 2003
    7.5
    High

    CVE-2003-0028

    Last Modified: 16 Apr 2026

    Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.

    Published: 19 Mar 2003
    5
    Medium

    CVE-2003-0072

    Last Modified: 16 Apr 2026

    The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes an out-of-bounds read of an array (aka "array overrun").

    Published: 19 Mar 2003
    5
    Medium

    CVE-2003-0128

    Last Modified: 16 Apr 2026

    The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.

    Published: 19 Mar 2003
    7.5
    High

    CVE-2003-0131

    Last Modified: 16 Apr 2026

    The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."

    Published: 19 Mar 2003
    7.5
    High

    CVE-2003-0139

    Last Modified: 16 Apr 2026

    Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."

    Published: 19 Mar 2003
    5
    Medium

    CVE-2003-0082

    Last Modified: 16 Apr 2026

    The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").

    Published: 19 Mar 2003
    5
    Medium

    CVE-2003-0129

    Last Modified: 16 Apr 2026

    Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.

    Published: 19 Mar 2003
    7.5
    High

    CVE-2003-0138

    Last Modified: 16 Apr 2026

    Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.

    Published: 19 Mar 2003
    10
    Critical

    CVE-2002-1428

    Last Modified: 16 Apr 2026

    index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1442

    Last Modified: 16 Apr 2026

    The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window's location to the toolbar's configuration URL, which bypasses the origin verification check.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1454

    Last Modified: 16 Apr 2026

    MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1457

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1458

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1483

    Last Modified: 16 Apr 2026

    db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1485

    Last Modified: 16 Apr 2026

    The AIM component of Trillian 0.73 and 0.74 allows remote attackers to cause a denial of service (crash) via certain strings such as "P > O < C".

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1504

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in WebServer 4 Everyone 1.22 allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a URL.

    Published: 18 Mar 2003
    6.2
    Medium

    CVE-2002-1512

    Last Modified: 16 Apr 2026

    xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1522

    Last Modified: 16 Apr 2026

    Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.

    Published: 18 Mar 2003
    6.4
    Medium

    CVE-2002-1544

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1557

    Last Modified: 16 Apr 2026

    Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.

    Published: 18 Mar 2003
    10
    Critical

    CVE-2002-1558

    Last Modified: 16 Apr 2026

    Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2003-0067

    Last Modified: 16 Apr 2026

    The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 18 Mar 2003
    4.3
    Medium

    CVE-2003-1203

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute script on other clients via the ?option parameter.

    Published: 18 Mar 2003
    10
    Critical

    CVE-2002-0690

    Last Modified: 16 Apr 2026

    Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.

    Published: 18 Mar 2003
    7.2
    High

    CVE-2002-1406

    Last Modified: 16 Apr 2026

    Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1411

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1429

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1441

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding request.

    Published: 18 Mar 2003
    4.3
    Medium

    CVE-2002-1455

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1456

    Last Modified: 16 Apr 2026

    Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1459

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1460

    Last Modified: 16 Apr 2026

    L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

    Published: 18 Mar 2003
    2.1
    Low

    CVE-2002-1470

    Last Modified: 16 Apr 2026

    SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1486

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.

    Published: 18 Mar 2003
    7.2
    High

    CVE-2002-1492

    Last Modified: 16 Apr 2026

    Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1499

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1523

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Daniel Arenz Mini Server 2.1.6 allows remote attackers to read arbitrary files via (1) ../ (dot-dot slash) or (2) ..\ (dot-dot backslash) sequences.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1525

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1545

    Last Modified: 16 Apr 2026

    CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1559

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2003-0104

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2003-0109

    Last Modified: 16 Apr 2026

    Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.

    Published: 18 Mar 2003
    10
    Critical

    CVE-2003-0143

    Last Modified: 16 Apr 2026

    The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-0387

    Last Modified: 16 Apr 2026

    Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1408

    Last Modified: 16 Apr 2026

    Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an easily guessable community name.

    Published: 18 Mar 2003
    2.1
    Low

    CVE-2002-1409

    Last Modified: 16 Apr 2026

    ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state."

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1415

    Last Modified: 16 Apr 2026

    Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1416

    Last Modified: 16 Apr 2026

    The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.

    Published: 18 Mar 2003