CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2003-1515

    Last Modified: 16 Apr 2026

    Origo ASR-8100 ADSL Router 3.21 has an administration service running on port 254 that does not require a password, which allows remote attackers to cause a denial of service by restoring the factory defaults.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1527

    Last Modified: 16 Apr 2026

    BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1536

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php and (2) the year parameter to calendar.php.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1544

    Last Modified: 16 Apr 2026

    Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1241

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script injected into the pseudo, email, and message parameters.

    Published: 31 Dec 2003
    5.8
    Medium

    CVE-2003-1238

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of the (1) Team, (2) News, and (3) Liens modules.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1230

    Last Modified: 16 Apr 2026

    The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when generating syncookies, which makes it easier for remote attackers to conduct brute force ISN guessing attacks and spoof legitimate traffic.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1222

    Last Modified: 16 Apr 2026

    BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1419

    Last Modified: 16 Apr 2026

    Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1420

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1421

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1422

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1423

    Last Modified: 16 Apr 2026

    Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1424

    Last Modified: 16 Apr 2026

    message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1425

    Last Modified: 16 Apr 2026

    guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1429

    Last Modified: 16 Apr 2026

    Buffer overflow in Proxomitron Naoko 4.4 allows remote attackers to execute arbitrary code via a long request.

    Published: 31 Dec 2003
    7.1
    High

    CVE-2003-1431

    Last Modified: 16 Apr 2026

    Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1433

    Last Modified: 16 Apr 2026

    Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1442

    Last Modified: 16 Apr 2026

    The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1438

    Last Modified: 16 Apr 2026

    Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1439

    Last Modified: 16 Apr 2026

    Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1440

    Last Modified: 16 Apr 2026

    SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1441

    Last Modified: 16 Apr 2026

    Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1436

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1445

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.

    Published: 31 Dec 2003
    1.9
    Low

    CVE-2003-1447

    Last Modified: 16 Apr 2026

    IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1448

    Last Modified: 16 Apr 2026

    Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1449

    Last Modified: 16 Apr 2026

    Aladdin Knowlege Systems eSafe Gateway 3.5.126.0 does not check the entire stream of Content Vectoring Protocol (CVP) data, which allows remote attackers to bypass virus protection.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1450

    Last Modified: 16 Apr 2026

    BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1451

    Last Modified: 16 Apr 2026

    Buffer overflow in Symantec Norton AntiVirus 2002 allows remote attackers to execute arbitrary code via an e-mail attachment with a compressed ZIP file that contains a file with a long filename.

    Published: 31 Dec 2003
    4.9
    Medium

    CVE-2003-1446

    Last Modified: 16 Apr 2026

    Buffer overflow in the save_into_file function in save.c for Rogue 5.2-2 allows local users to execute arbitrary code with games group privileges by setting a long HOME environment variable and invoking the save game function with a ~ (tilde).

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1459

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php.

    Published: 31 Dec 2003
    3.6
    Low

    CVE-2003-1460

    Last Modified: 16 Apr 2026

    Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1461

    Last Modified: 16 Apr 2026

    Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1462

    Last Modified: 16 Apr 2026

    mod_survey 3.0.0 through 3.0.15-pre6 does not check whether a survey exists before creating a subdirectory for it, which allows remote attackers to cause a denial of service (disk consumption and possible crash).

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1457

    Last Modified: 16 Apr 2026

    Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1458

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1466

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1468

    Last Modified: 16 Apr 2026

    The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.

    Published: 31 Dec 2003
    9
    Critical

    CVE-2003-1470

    Last Modified: 16 Apr 2026

    Buffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a CREATE command with a long mailbox name.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1476

    Last Modified: 16 Apr 2026

    Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1478

    Last Modified: 16 Apr 2026

    Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1479

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in webcamXP 1.02.432 and 1.02.535 allows remote attackers to inject arbitrary web script or HTML via the message field.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1480

    Last Modified: 16 Apr 2026

    MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.

    Published: 31 Dec 2003
    5.8
    Medium

    CVE-2003-1481

    Last Modified: 16 Apr 2026

    CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1482

    Last Modified: 16 Apr 2026

    The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1477

    Last Modified: 16 Apr 2026

    MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects."

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1490

    Last Modified: 16 Apr 2026

    SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1491

    Last Modified: 16 Apr 2026

    Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1492

    Last Modified: 16 Apr 2026

    Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.

    Published: 31 Dec 2003