CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2003-1493

    Last Modified: 16 Apr 2026

    Memory leak in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (memory exhaustion) via crafted TCP packets.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1494

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in HP OpenView Network Node Manager (NNM) 6.2 and 6.4 allows remote attackers to cause a denial of service (CPU consumption) via a crafted TCP packet.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1526

    Last Modified: 16 Apr 2026

    PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1498

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject arbitrary web script or HTML via the zoom_query parameter.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1501

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the file upload CGI of Gast Arbeiter 1.3 allows remote attackers to write arbitrary files via a .. (dot dot) in the req_file parameter.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1502

    Last Modified: 16 Apr 2026

    mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1503

    Last Modified: 16 Apr 2026

    Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1504

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1505

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.

    Published: 31 Dec 2003
    6.3
    Medium

    CVE-2003-1497

    Last Modified: 16 Apr 2026

    Buffer overflow in the system log viewer of Linksys BEFSX41 1.44.3 allows remote attackers to cause a denial of service via an HTTP request with a long Log_Page_Num variable.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1510

    Last Modified: 16 Apr 2026

    TinyWeb 1.9 allows remote attackers to cause a denial of service (CPU consumption) via a ".%00." in an HTTP GET request to the cgi-bin directory.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1513

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1514

    Last Modified: 16 Apr 2026

    eMule 0.29c allows remote attackers to cause a denial of service (crash) via a long password, possibly due to a buffer overflow.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1508

    Last Modified: 16 Apr 2026

    Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filename.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1520

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1521

    Last Modified: 16 Apr 2026

    Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1522

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to the admin/index.html page.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1523

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly other attack vectors.

    Published: 31 Dec 2003
    6.3
    Medium

    CVE-2003-1524

    Last Modified: 16 Apr 2026

    PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access data on another user's PGP partition.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1525

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1531

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in testcgi.exe in Lilikoi Software Ceilidh 2.70 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1532

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1533

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1534

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1535

    Last Modified: 16 Apr 2026

    Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1539

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1540

    Last Modified: 16 Apr 2026

    WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1541

    Last Modified: 16 Apr 2026

    PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1542

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1543

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1538

    Last Modified: 16 Apr 2026

    susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1547

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1548

    Last Modified: 16 Apr 2026

    MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1549

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1550

    Last Modified: 16 Apr 2026

    XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOption parameter, which reveals the installation path in an error message.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1551

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Novell GroupWise 6 SP3 WebAccess before Revision F has unknown impact and attack vectors related to "malicious script."

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1552

    Last Modified: 16 Apr 2026

    Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1556

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI City CC GuestBook allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) homepage_title (webpage title) parameters.

    Published: 31 Dec 2003
    7.6
    High

    CVE-2003-1557

    Last Modified: 16 Apr 2026

    Off-by-one buffer overflow in spamc of SpamAssassin 2.40 through 2.43, when using BSMTP mode ("-B"), allows remote attackers to execute arbitrary code via email containing headers with leading "." characters.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1558

    Last Modified: 16 Apr 2026

    Buffer overflow in httpd.c of fnord 1.6 allows remote attackers to create a denial of service (crash) and possibly execute arbitrary code via a long CGI request passed to the do_cgi function.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1559

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1560

    Last Modified: 16 Apr 2026

    Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1561

    Last Modified: 16 Apr 2026

    Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1555

    Last Modified: 16 Apr 2026

    ScozNet ScozBook 1.1 BETA allows remote attackers to obtain sensitive information via an invalid PG parameter in view.php, which reveals the installation path in an error message.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-0885

    Last Modified: 16 Apr 2026

    Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack.

    Published: 31 Dec 2003
    1.2
    Low

    CVE-2003-1073

    Last Modified: 16 Apr 2026

    A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1082

    Last Modified: 16 Apr 2026

    Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-1068.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1083

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1104

    Last Modified: 16 Apr 2026

    Buffer overflow in IBM Tivoli Firewall Toolbox (TFST) 1.2 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1131

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2003