search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2003-01-31 2003-01-28 2003-04-04 VU#684563 MIT Kerberos V5 allows inter-realm user impersonation by malicious realm controllers with shared keys
2003-01-31 2003-01-28 2003-02-01 VU#787523 MIT Kerberos V5 KDC logging routines use unsafe format strings
2003-02-04 2003-01-15 2003-05-30 VU#149953 ISC "dhcrelay" fails to limit hop count when malicious bootp packet is received
2003-02-05 2003-01-02 2003-02-06 VU#855635 Sun Solaris lockd(1M) daemon vulnerable to DoS
2003-02-06 2003-02-05 2003-02-13 VU#400577 Microsoft Internet Explorer allows arbitrary local file reading via "showHelp()" function
2003-02-07 2003-02-06 2003-02-07 VU#666073 AbsoluteTelnet vulnerable to buffer overflow via overly long window title
2003-02-11 2003-02-07 2003-02-11 VU#134025 kernel-utils sets insecure permissions on "uml_net" utility
2003-02-12 2003-01-21 2003-02-12 VU#825177 Apache allows arbitrary code execution via crafted POST request containing MS-DOS device name
2003-02-12 2003-01-21 2003-02-12 VU#979793 Apache vulnerable to DoS via request for MS-DOS device
2003-02-14 2003-02-11 2003-07-24 VU#849993 Some implementations of mod_dav contain a format string vulnerability in "ap_log_rerror()" function
2003-02-14 2001-01-28 2003-02-14 VU#146704 Hyperseek 2000 hsx.cgi does not adequately filter user input disclosing directory listings and file contents
2003-02-17 2003-02-17 2003-02-21 VU#354387 Yahoo! Mobile service discloses random sensitive information to unauthorized users
2003-02-18 2003-02-11 2003-02-19 VU#953746 Oracle9i Database contains remotely exploitable buffer overflow in "ORACLE.EXE"
2003-02-18 2003-02-11 2003-02-19 VU#840666 Oracle9i Database contains remotely exploitable buffer overflow in "TO_TIMESTAMP_TZ" function
2003-02-18 2003-02-11 2003-02-19 VU#743954 Oracle9i Database contains remotely exploitable buffer overflow in "TZ_OFFSET" function

Sponsored by CISA.