CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2004-0112

    Last Modified: 16 Apr 2026

    The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

    Published: 17 Mar 2004
    7.5
    High

    CVE-2002-1577

    Last Modified: 16 Apr 2026

    SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM accounts.

    Published: 16 Mar 2004
    7.5
    High

    CVE-2002-1578

    Last Modified: 16 Apr 2026

    The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database and executing queries against the database, which is not password-protected.

    Published: 16 Mar 2004
    4.6
    Medium

    CVE-2003-0202

    Last Modified: 16 Apr 2026

    The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 16 Mar 2004
    7.5
    High

    CVE-2003-0513

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Internet Explorer to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

    Published: 16 Mar 2004
    7.5
    High

    CVE-2003-0514

    Last Modified: 16 Apr 2026

    Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

    Published: 16 Mar 2004
    7.5
    High

    CVE-2003-0593

    Last Modified: 16 Apr 2026

    Opera allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Opera to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

    Published: 16 Mar 2004
    7.5
    High

    CVE-2003-1036

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the AGate component for SAP Internet Transaction Server (ITS) allow remote attackers to execute arbitrary code via long (1) ~command, (2) ~runtimemode, or (3) ~session parameters, or (4) a long HTTP Content-Type header.

    Published: 16 Mar 2004
    7.2
    High

    CVE-2002-1576

    Last Modified: 16 Apr 2026

    lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver program.

    Published: 16 Mar 2004
    7.5
    High

    CVE-2003-1039

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the mySAP.com architecture for SAP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) Message Server, (2) Web Dispatcher, or (3) Application Server.

    Published: 16 Mar 2004
    7
    High

    CVE-2004-0217

    Last Modified: 16 Apr 2026

    The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.

    Published: 16 Mar 2004
    4.3
    Medium

    CVE-2004-1825

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.

    Published: 16 Mar 2004
    7.5
    High

    CVE-2004-1826

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Mar 2004
    5
    Medium

    CVE-2002-1579

    Last Modified: 16 Apr 2026

    SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error.

    Published: 16 Mar 2004
    7.2
    High

    CVE-2003-0257

    Last Modified: 16 Apr 2026

    Format string vulnerability in the printer capability for IBM AIX .3, 5.1, and 5.2 allows local users to gain printq or root privileges.

    Published: 16 Mar 2004
    7.2
    High

    CVE-2003-1033

    Last Modified: 16 Apr 2026

    The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.

    Published: 16 Mar 2004
    4.6
    Medium

    CVE-2003-1034

    Last Modified: 16 Apr 2026

    The RPM installation of SAP DB 7.x creates the (1) dbmsrv or (2) lserver programs with world-writable permissions, which allows local users to gain privileges by modifying those programs.

    Published: 16 Mar 2004
    7.5
    High

    CVE-2003-1037

    Last Modified: 16 Apr 2026

    Format string vulnerability in the WGate component for SAP Internet Transaction Server (ITS) allows remote attackers to execute arbitrary code via a high "trace level."

    Published: 16 Mar 2004
    7.5
    High

    CVE-2004-0224

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."

    Published: 16 Mar 2004
    7.5
    High

    CVE-2003-1035

    Last Modified: 16 Apr 2026

    The default installation of SAP R/3 46C/D allows remote attackers to bypass account locking by using the RFC API instead of the SAPGUI to conduct a brute force password guessing attack, which does not lock out the account like the SAPGUI does.

    Published: 16 Mar 2004
    5
    Medium

    CVE-2003-1038

    Last Modified: 16 Apr 2026

    The AGate component for SAP Internet Transaction Server (ITS) allows remote attackers to obtain sensitive information via a ~command parameter with an AgateInstallCheck value, which provides a list of installed DLLs and full pathnames.

    Published: 16 Mar 2004
    5
    Medium

    CVE-2004-0171

    Last Modified: 16 Apr 2026

    FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.

    Published: 15 Mar 2004
    7.5
    High

    CVE-2004-0193

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.

    Published: 15 Mar 2004
    4.3
    Medium

    CVE-2004-1817

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) search field.

    Published: 15 Mar 2004
    6.8
    Medium

    CVE-2004-1818

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.

    Published: 15 Mar 2004
    5
    Medium

    CVE-2004-1819

    Last Modified: 16 Apr 2026

    4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message.

    Published: 15 Mar 2004
    7.5
    High

    CVE-2004-1820

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.

    Published: 15 Mar 2004
    7.5
    High

    CVE-2004-1821

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter.

    Published: 15 Mar 2004
    4.3
    Medium

    CVE-2004-1822

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_REFERER parameter to login.php, (2) HTTP_REFERER parameter to register.php, or (3) target parameter to profile.php.

    Published: 15 Mar 2004
    5
    Medium

    CVE-2004-1816

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).

    Published: 15 Mar 2004
    4.3
    Medium

    CVE-2004-1827

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.

    Published: 15 Mar 2004
    7.5
    High

    CVE-2004-0167

    Last Modified: 16 Apr 2026

    DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.

    Published: 15 Mar 2004
    5
    Medium

    CVE-2004-0165

    Last Modified: 16 Apr 2026

    Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbitrary pppd process data, including PAP or CHAP authentication credentials, to gain privileges.

    Published: 15 Mar 2004
    7.5
    High

    CVE-2004-0190

    Last Modified: 16 Apr 2026

    Symantec FireWall/VPN Appliance model 200 records a cleartext password for the password administration page, which may be cached on the administrator's local system or in a proxy, which allows attackers to steal the password and gain privileges.

    Published: 15 Mar 2004
    7.2
    High

    CVE-2004-0188

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Calife 2.8.5 and earlier may allow local users to execute arbitrary code via a long password.

    Published: 15 Mar 2004
    7.5
    High

    CVE-2004-0159

    Last Modified: 16 Apr 2026

    Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.

    Published: 15 Mar 2004
    5
    Medium

    CVE-2004-0169

    Last Modified: 16 Apr 2026

    QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long User-Agent fields, which causes an Assert error to be triggered in the BufferIsFull function.

    Published: 15 Mar 2004
    7.2
    High

    CVE-2004-0186

    Last Modified: 16 Apr 2026

    smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted.

    Published: 15 Mar 2004
    5
    Medium

    CVE-2004-1815

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).

    Published: 15 Mar 2004
    5
    Medium

    CVE-2004-1358

    Last Modified: 16 Apr 2026

    The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.

    Published: 12 Mar 2004
    10
    Critical

    CVE-2004-1769

    Last Modified: 16 Apr 2026

    The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.

    Published: 11 Mar 2004
    10
    Critical

    CVE-2004-1770

    Last Modified: 16 Apr 2026

    The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.

    Published: 11 Mar 2004
    6.8
    Medium

    CVE-2003-1199

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Published: 11 Mar 2004
    5
    Medium

    CVE-2005-0760

    Last Modified: 16 Apr 2026

    The TIFF decoder in ImageMagick before 6.0 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.

    Published: 11 Mar 2004
    5
    Medium

    CVE-2005-0759

    Last Modified: 16 Apr 2026

    ImageMagick before 6.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image with an invalid tag.

    Published: 11 Mar 2004
    7.5
    High

    CVE-2003-0601

    Last Modified: 16 Apr 2026

    Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.

    Published: 10 Mar 2004
    4.6
    Medium

    CVE-2003-0607

    Last Modified: 16 Apr 2026

    Buffer overflow in xconq 7.4.1 allows local users to become part of the "games" group via the (1) USER or (2) DISPLAY environment variables.

    Published: 10 Mar 2004
    4.6
    Medium

    CVE-2003-0612

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to crafty.bin.

    Published: 10 Mar 2004
    7.5
    High

    CVE-2003-0444

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in GTKSee 0.5 and 0.5.1 allows remote attackers to execute arbitrary code via a PNG image of certain color depths.

    Published: 10 Mar 2004
    7.5
    High

    CVE-2003-0796

    Last Modified: 16 Apr 2026

    Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled.

    Published: 10 Mar 2004