CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2004-0037

    Last Modified: 16 Apr 2026

    FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.

    Published: 8 Jan 2004
    7.5
    High

    CVE-2003-1023

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.

    Published: 6 Jan 2004
    7.5
    High

    CVE-2003-0990

    Last Modified: 16 Apr 2026

    The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell metacharacters in the "To:" field.

    Published: 6 Jan 2004
    7.2
    High

    CVE-2003-1024

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.

    Published: 6 Jan 2004
    4.3
    Medium

    CVE-2003-1025

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."

    Published: 6 Jan 2004
    7.2
    High

    CVE-2003-0985

    Last Modified: 16 Apr 2026

    The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.

    Published: 5 Jan 2004
    5
    Medium

    CVE-2004-1786

    Last Modified: 16 Apr 2026

    PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.

    Published: 4 Jan 2004
    5
    Medium

    CVE-2004-0057

    Last Modified: 16 Apr 2026

    The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.

    Published: 4 Jan 2004
    5
    Medium

    CVE-2004-0055

    Last Modified: 16 Apr 2026

    The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.

    Published: 4 Jan 2004
    7.5
    High

    CVE-2004-1785

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.

    Published: 3 Jan 2004
    7.5
    High

    CVE-2004-1784

    Last Modified: 16 Apr 2026

    Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 3 Jan 2004
    4.3
    Medium

    CVE-2003-1553

    Last Modified: 16 Apr 2026

    Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1256

    Last Modified: 16 Apr 2026

    aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include parameter to reference a URL on a remote web server that contains para_langue.php.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1257

    Last Modified: 16 Apr 2026

    find_theni_home.php in E-theni allows remote attackers to obtain sensitive system information via a URL request which executes phpinfo.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1258

    Last Modified: 16 Apr 2026

    activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1267

    Last Modified: 16 Apr 2026

    GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1268

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1351

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in edittag.cgi in EditTag 1.1 allows remote attackers to read arbitrary files via a "%2F.." (encoded slash dot dot) in the file parameter.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1297

    Last Modified: 16 Apr 2026

    Easy File Sharing (EFS) Web Server 1.2 stores the (1) option.ini (aka options.ini) file and (2) log directory under the web root with insufficient access control, which allows remote attackers to obtain sensitive information including an SMTP account username and password hash, the server configuration, and server log files.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1305

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page.

    Published: 31 Dec 2003
    2.6
    Low

    CVE-2003-1306

    Last Modified: 16 Apr 2026

    Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1314

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1315

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in auth.php in Land Down Under (LDU) v601 and earlier allows remote attackers to execute arbitrary SQL commands.

    Published: 31 Dec 2003
    6.5
    Medium

    CVE-2003-1340

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid (user) cookie to modules.php; and allow remote attackers to execute arbitrary SQL commands via an aid (admin) cookie to the Web_Links module in a (2) viewlink, (3) MostPopular, or (4) NewLinksDate action, different vectors than CVE-2003-0279.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1348

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1349

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in NITE ftp-server (NiteServer) 1.83 allows remote attackers to list arbitrary directories via a "\.." (backslash dot dot) in the CD (CWD) command.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1350

    Last Modified: 16 Apr 2026

    List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1367

    Last Modified: 16 Apr 2026

    The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1369

    Last Modified: 16 Apr 2026

    Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1372

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1381

    Last Modified: 16 Apr 2026

    Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1405

    Last Modified: 16 Apr 2026

    DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1406

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1410

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1415

    Last Modified: 16 Apr 2026

    NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1416

    Last Modified: 16 Apr 2026

    BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.

    Published: 31 Dec 2003
    4.4
    Medium

    CVE-2003-1417

    Last Modified: 16 Apr 2026

    nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1434

    Last Modified: 16 Apr 2026

    login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1437

    Last Modified: 16 Apr 2026

    BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.

    Published: 31 Dec 2003
    4.4
    Medium

    CVE-2003-1443

    Last Modified: 16 Apr 2026

    Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.

    Published: 31 Dec 2003
    3.6
    Low

    CVE-2003-1452

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1453

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1454

    Last Modified: 16 Apr 2026

    Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1469

    Last Modified: 16 Apr 2026

    The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1472

    Last Modified: 16 Apr 2026

    Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long banner.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1473

    Last Modified: 16 Apr 2026

    Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1474

    Last Modified: 16 Apr 2026

    slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1484

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1486

    Last Modified: 16 Apr 2026

    Phorum 3.4 through 3.4.2 allows remote attackers to obtain the full path of the web server via an incorrect HTTP request to (1) smileys.php, (2) quick_listrss.php, (3) purge.php, (4) news.php, (5) memberlist.php, (6) forum_listrss.php, (7) forum_list_rdf.php, (8) forum_list.php, or (9) move.php, which leaks the information in an error message.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1511

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet.

    Published: 31 Dec 2003