Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2003-06-30 CVE-2003-0403 Denial Of Service vulnerability in Vignette Content Suite, Storyserver and Vignette
Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.
network
low complexity
vignette
7.5
2003-06-19 CVE-2003-1067 Local Security vulnerability in RETIRED: Oracle Solaris
Multiple buffer overflows in the (1) dbm_open function, as used in ndbm and dbm, and the (2) dbminit function in Solaris 2.6 through 9 allow local users to gain root privileges via long arguments to Xsun or other programs that use these functions.
local
low complexity
sun
7.2
2003-06-17 CVE-2003-1086 Remote Security vulnerability in Pmachine Free and Pmachine PRO
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_path parameter to reference a URL on a remote web server that contains the code.
network
low complexity
pmachine
7.5
2003-06-16 CVE-2003-0378 Unspecified vulnerability in Apple mac OS X
The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.
network
low complexity
apple
7.5
2003-06-16 CVE-2003-0371 Denial-Of-Service vulnerability in Prishtina Soft Prishtina FTP V.1
Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP banner.
network
low complexity
prishtina-soft
7.5
2003-06-16 CVE-2003-0370 Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
network
low complexity
apple kde redhat turbolinux
7.5
2003-06-16 CVE-2003-0354 Unspecified vulnerability in Redhat Linux
Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.
network
low complexity
redhat
7.5
2003-06-16 CVE-2003-0344 Unspecified vulnerability in Microsoft IE and Internet Explorer
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.
network
low complexity
microsoft
7.5
2003-06-16 CVE-2003-0315 Denial-Of-Service vulnerability in Snowblind.Net Snowblind web Server 1.0
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.
network
low complexity
snowblind-net
7.5
2003-06-16 CVE-2003-0299 Denial-Of-Service vulnerability in Balsa
The IMAP Client, as used in mutt 1.4.1 and Balsa 2.0.10, allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large mailbox size values that cause either integer signedness errors or integer overflow errors.
network
low complexity
mutt stuart-parmenter
7.5