Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2004-01-05 CVE-2003-1000 NULL Pointer Dereference vulnerability in Xchat 2.0.6
xchat 2.0.6 allows remote attackers to cause a denial of service (crash) via a passive DCC request with an invalid ID number, which causes a null dereference.
network
low complexity
xchat CWE-476
7.5
2004-01-05 CVE-2003-0999 Local Security vulnerability in Solaris
Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.
local
low complexity
sun
7.2
2004-01-05 CVE-2003-0995 Denial-Of-Service vulnerability in Windows 2000 Datacenter Server
Buffer overflow in the Microsoft Message Queue Manager (MSQM) allows remote attackers to cause a denial of service (RPC service crash) via a queue registration request.
network
low complexity
microsoft
7.5
2004-01-05 CVE-2003-0983 Remote Security vulnerability in Cisco products
Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) when a local DHCP server is unavailable, a DHCP server on the manufacturer's test network.
network
low complexity
cisco
7.5
2004-01-05 CVE-2003-0982 Remote Buffer Overrun vulnerability in Cisco ACNS Authentication Library
Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password.
network
low complexity
cisco
7.5
2004-01-05 CVE-2003-0978 Unspecified vulnerability in GNU Privacy Guard
Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.
network
low complexity
gnu
7.5
2004-01-05 CVE-2003-0977 CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.
network
low complexity
cvs slackware
7.5
2004-01-05 CVE-2003-0963 Unspecified vulnerability in Alexander V. Lukyanov Lftp
Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.
network
low complexity
alexander-v-lukyanov
7.5
2004-01-03 CVE-2004-1785 SQL Injection vulnerability in Invision Power Board Calendar.PHP
SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.
network
low complexity
invision-power-services
7.5
2004-01-03 CVE-2004-1784 Buffer Overflow vulnerability in Webcam Corp Webcam Watchdog 1.0/1.1/3.63
Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.
network
low complexity
webcam-corp
7.5