CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2003-0819

    Last Modified: 16 Apr 2026

    Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2003-1030

    Last Modified: 16 Apr 2026

    Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long pre-authentication request to TCP port 6129.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2004-0054

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2004-0056

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gateway allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

    Published: 15 Jan 2004
    5
    Medium

    CVE-2004-0060

    Last Modified: 16 Apr 2026

    WWW File Share Pro 2.42 and earlier allows remote attackers to cause a denial of service (crash) via a large POST request.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2004-0061

    Last Modified: 16 Apr 2026

    WWW File Share Pro 2.42 and earlier allows remote attackers to bypass directory access restrictions via (1) a URL with a trailing . (dot), or (2) a URI with a leading slash or backslash character.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2004-0062

    Last Modified: 16 Apr 2026

    Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity.

    Published: 15 Jan 2004
    2.1
    Low

    CVE-2004-0064

    Last Modified: 16 Apr 2026

    The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2004-0065

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpGedView before 2.65 allow remote attackers to execute arbitrary SQL via (1) timeline.php and (2) placelist.php.

    Published: 15 Jan 2004
    5
    Medium

    CVE-2004-0059

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2004-0069

    Last Modified: 16 Apr 2026

    Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.

    Published: 15 Jan 2004
    5
    Medium

    CVE-2004-0071

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.

    Published: 15 Jan 2004
    5
    Medium

    CVE-2004-0072

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.

    Published: 15 Jan 2004
    5
    Medium

    CVE-2004-0066

    Last Modified: 16 Apr 2026

    phpGedView before 2.65 allows remote attackers to obtain the absolute path of the web server via malformed parameters to (1) indilist.php, (2) famlist.php, (3) placelist.php, (4) imageview.php, (5) timeline.php, (6) clippings.php, (7) login.php, and (8) gdbi.php.

    Published: 15 Jan 2004
    5
    Medium

    CVE-2005-1247

    Last Modified: 16 Apr 2026

    webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exploit for the OpenSSL ASN.1 parsing vulnerability.

    Published: 15 Jan 2004
    2.6
    Low

    CVE-2004-0837

    Last Modified: 16 Apr 2026

    MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.

    Published: 15 Jan 2004
    7.5
    High

    CVE-2004-0041

    Last Modified: 16 Apr 2026

    The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.

    Published: 14 Jan 2004
    4.3
    Medium

    CVE-2004-0046

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script or HTML via a GET request containing a terminating '"' (double quote) character.

    Published: 14 Jan 2004
    2.1
    Low

    CVE-2002-0712

    Last Modified: 16 Apr 2026

    Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0119

    Last Modified: 16 Apr 2026

    The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which allows remote attackers to directly connect to the daemon and conduct unauthorized activities.

    Published: 14 Jan 2004
    5
    Medium

    CVE-2003-0368

    Last Modified: 16 Apr 2026

    Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.

    Published: 14 Jan 2004
    4.6
    Medium

    CVE-2002-0034

    Last Modified: 16 Apr 2026

    The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0823

    Last Modified: 16 Apr 2026

    Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0814

    Last Modified: 16 Apr 2026

    Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0815

    Last Modified: 16 Apr 2026

    Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0816

    Last Modified: 16 Apr 2026

    Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0817

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.

    Published: 14 Jan 2004
    4.6
    Medium

    CVE-2004-1124

    Last Modified: 16 Apr 2026

    Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.

    Published: 14 Jan 2004
    7.2
    High

    CVE-2004-1764

    Last Modified: 16 Apr 2026

    Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.

    Published: 14 Jan 2004
    2.1
    Low

    CVE-2003-0175

    Last Modified: 16 Apr 2026

    SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0902

    Last Modified: 16 Apr 2026

    Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers to execute arbitrary commands.

    Published: 14 Jan 2004
    4.6
    Medium

    CVE-2003-0949

    Last Modified: 16 Apr 2026

    xsok 1.02 does not properly drop privileges before finding and executing the "gunzip" program, which allows local users to execute arbitrary commands.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2004-0017

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.

    Published: 14 Jan 2004
    5
    Medium

    CVE-2004-0042

    Last Modified: 16 Apr 2026

    vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2004-0043

    Last Modified: 16 Apr 2026

    Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0988

    Last Modified: 16 Apr 2026

    Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0966

    Last Modified: 16 Apr 2026

    Buffer overflow in the frm command in elm 2.5.6 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code via a long Subject line.

    Published: 14 Jan 2004
    7.5
    High

    CVE-2003-0989

    Last Modified: 16 Apr 2026

    tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.

    Published: 14 Jan 2004
    5
    Medium

    CVE-2004-0164

    Last Modified: 16 Apr 2026

    KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.

    Published: 13 Jan 2004
    7.2
    High

    CVE-2004-0001

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.

    Published: 13 Jan 2004
    2.1
    Low

    CVE-2004-1000

    Last Modified: 16 Apr 2026

    lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.

    Published: 10 Jan 2004
    9.8
    Critical

    CVE-2004-0030

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.

    Published: 8 Jan 2004
    4.6
    Medium

    CVE-2004-0029

    Last Modified: 16 Apr 2026

    Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.

    Published: 8 Jan 2004
    5
    Medium

    CVE-2003-0696

    Last Modified: 16 Apr 2026

    The getipnodebyname() API in AIX 5.1 and 5.2 does not properly close sockets, which allows attackers to cause a denial of service (resource exhaustion).

    Published: 8 Jan 2004
    9.3
    Critical

    CVE-2003-1026

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."

    Published: 8 Jan 2004
    10
    Critical

    CVE-2003-1027

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."

    Published: 8 Jan 2004
    5
    Medium

    CVE-2003-1028

    Last Modified: 16 Apr 2026

    The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random names, as demonstrated by threadid10008.

    Published: 8 Jan 2004
    4.3
    Medium

    CVE-2004-0034

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.4.5 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the phorum_check_xss function in common.php, (2) the EditError variable in profile.php, and (3) the Error variable in login.php.

    Published: 8 Jan 2004
    6
    Medium

    CVE-2003-0904

    Last Modified: 16 Apr 2026

    Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.

    Published: 8 Jan 2004
    7.5
    High

    CVE-2004-0014

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the nd WebDAV interface 0.8.2 and earlier allows remote web servers to execute arbitrary code via certain long strings.

    Published: 8 Jan 2004