Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2003-02-19 CVE-2003-0057 Buffer Overflow vulnerability in Hypermail Message Attachment
Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.
network
low complexity
hypermail
7.5
2003-02-19 CVE-2003-0056 Unspecified vulnerability in Slocate 2.5/2.6
Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.
local
low complexity
slocate
7.2
2003-02-19 CVE-2003-0040 SQL Injection vulnerability in Courier-IMAP Username
SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.
network
low complexity
double-precision-incorporated inter7
7.5
2003-02-19 CVE-2003-0019 Unspecified vulnerability in Redhat Linux 8.0
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g.
local
low complexity
redhat
7.2
2003-02-19 CVE-2003-0004 Privilege Escalation vulnerability in Microsoft Windows XP Redirector
Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.
local
low complexity
microsoft
7.2
2003-02-19 CVE-2002-1160 Unspecified vulnerability in Redhat Linux
The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.
local
low complexity
redhat
7.2
2003-02-07 CVE-2003-0037 Remote Memory Corruption vulnerability in Noffle
Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.
network
low complexity
noffle
7.5
2003-02-07 CVE-2003-0035 Local Printer Name Buffer Overflow vulnerability in Robert Krawitz Escputil 1.15.2.2
Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.
local
low complexity
robert-krawitz
7.2
2003-02-07 CVE-2003-0034 Buffer Overflow vulnerability in Jean-Jacques Sarton Mtink 0.9.32/0.9.33/0.9.52
Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.
local
low complexity
jean-jacques-sarton
7.2
2003-02-07 CVE-2003-0015 Double Free vulnerability in multiple products
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.
network
low complexity
freebsd cvs CWE-415
7.5