CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2003-1134

    Last Modified: 16 Apr 2026

    Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1153

    Last Modified: 16 Apr 2026

    byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1154

    Last Modified: 16 Apr 2026

    MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1155

    Last Modified: 16 Apr 2026

    X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1156

    Last Modified: 16 Apr 2026

    Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1165

    Last Modified: 16 Apr 2026

    Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1166

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1167

    Last Modified: 16 Apr 2026

    misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their privileges by modifying the PATH variable to reference a malicious killall program.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1177

    Last Modified: 16 Apr 2026

    Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1213

    Last Modified: 16 Apr 2026

    The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure access control, which allows remote attackers to obtain sensitive information via a direct request to database/db2000.mdb.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1362

    Last Modified: 16 Apr 2026

    Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1357

    Last Modified: 16 Apr 2026

    ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.

    Published: 31 Dec 2003
    3.3
    Low

    CVE-2003-1366

    Last Modified: 16 Apr 2026

    chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1368

    Last Modified: 16 Apr 2026

    Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1375

    Last Modified: 16 Apr 2026

    Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1376

    Last Modified: 16 Apr 2026

    WinZip 8.0 uses weak random number generation for password protected ZIP files, which allows local users to brute force the encryption keys and extract the data from the zip file by guessing the state of the stream coder.

    Published: 31 Dec 2003
    8.3
    High

    CVE-2003-1377

    Last Modified: 16 Apr 2026

    Buffer overflow in the reverse DNS lookup of Smart IRC Daemon (SIRCD) 0.4.0 and 0.4.4 allows remote attackers to execute arbitrary code via a client with a long hostname.

    Published: 31 Dec 2003
    8.8
    High

    CVE-2003-1378

    Last Modified: 16 Apr 2026

    Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1379

    Last Modified: 16 Apr 2026

    clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which reveals /var/log/messages.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1483

    Last Modified: 16 Apr 2026

    FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1374

    Last Modified: 16 Apr 2026

    Buffer overflow in disable of HP-UX 11.0 may allow local users to execute arbitrary code via a long argument to the (1) -r or (2)-c options.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1387

    Last Modified: 16 Apr 2026

    Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.

    Published: 31 Dec 2003
    9.3
    Critical

    CVE-2003-1388

    Last Modified: 16 Apr 2026

    Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1390

    Last Modified: 16 Apr 2026

    RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the passphrase.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1391

    Last Modified: 16 Apr 2026

    RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers to guess the passphrase.

    Published: 31 Dec 2003
    6.6
    Medium

    CVE-2003-1392

    Last Modified: 16 Apr 2026

    CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.

    Published: 31 Dec 2003
    8.5
    High

    CVE-2003-1393

    Last Modified: 16 Apr 2026

    Buffer overflow in Gupta SQLBase 8.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long EXECUTE command.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1396

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.

    Published: 31 Dec 2003
    9.3
    Critical

    CVE-2003-1398

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).

    Published: 31 Dec 2003
    1.9
    Low

    CVE-2003-1399

    Last Modified: 16 Apr 2026

    eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.

    Published: 31 Dec 2003
    5.8
    Medium

    CVE-2003-1401

    Last Modified: 16 Apr 2026

    login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1402

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1411

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1413

    Last Modified: 16 Apr 2026

    parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1414

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1089

    Last Modified: 16 Apr 2026

    index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1091

    Last Modified: 16 Apr 2026

    Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1092

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1093

    Last Modified: 16 Apr 2026

    BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationException.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1094

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1098

    Last Modified: 16 Apr 2026

    The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1099

    Last Modified: 16 Apr 2026

    shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1100

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allow remote attackers to inject arbitrary web script or HTML via certain vectors.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1101

    Last Modified: 16 Apr 2026

    Hummingbird CyberDOCS 3.5.1, 3.9, and 4.0 allows remote attackers to obtain the full path of the DM Web Server via invalid login credentials, which reveals the path in an error message.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1102

    Last Modified: 16 Apr 2026

    Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1103

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1108

    Last Modified: 16 Apr 2026

    The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1111

    Last Modified: 16 Apr 2026

    The Session Initiation Protocol (SIP) implementation in multiple dynamicsoft products including y and certain demo products for AppEngine allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

    Published: 31 Dec 2003
    5.1
    Medium

    CVE-2003-1107

    Last Modified: 16 Apr 2026

    The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1116

    Last Modified: 16 Apr 2026

    The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.

    Published: 31 Dec 2003