CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2003-1117

    Last Modified: 16 Apr 2026

    Buffer overflow in RealSystem Server 6.x, 7.x and 8.x, and RealSystem Proxy 8.x, related to URL error handling, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1118

    Last Modified: 16 Apr 2026

    Buffer overflow in the SETI@home client 3.03 and other versions allows remote attackers to cause a denial of service (client crash) and execute arbitrary code via a spoofed server response containing a long string followed by a \n (newline) character.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1119

    Last Modified: 16 Apr 2026

    SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.

    Published: 31 Dec 2003
    3.7
    Low

    CVE-2003-1120

    Last Modified: 16 Apr 2026

    Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1124

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Sun Management Center (SunMC) 2.1.1, 3.0, and 3.0 Revenue Release (RR), when installed and run by root, allows local users to create or modify arbitrary files.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1125

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1126

    Last Modified: 16 Apr 2026

    Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1127

    Last Modified: 16 Apr 2026

    Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1128

    Last Modified: 16 Apr 2026

    XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086.

    Published: 31 Dec 2003
    2.6
    Low

    CVE-2003-1129

    Last Modified: 16 Apr 2026

    Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1123

    Last Modified: 16 Apr 2026

    Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.

    Published: 31 Dec 2003
    2.6
    Low

    CVE-2003-1135

    Last Modified: 16 Apr 2026

    Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1133

    Last Modified: 16 Apr 2026

    Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.

    Published: 31 Dec 2003
    Unknown

    CVE-2003-1147

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0955. Reason: This candidate is a duplicate of CVE-2003-0955. Notes: All CVE users should reference CVE-2003-0955 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1161

    Last Modified: 16 Apr 2026

    exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1162

    Last Modified: 16 Apr 2026

    index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1163

    Last Modified: 16 Apr 2026

    hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1164

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1158

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1172

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1173

    Last Modified: 16 Apr 2026

    Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1174

    Last Modified: 16 Apr 2026

    Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1175

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web script or HTML via the vo parameter.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1176

    Last Modified: 16 Apr 2026

    post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1171

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the sec_filter_out function in mod_security 1.7RC1 through 1.7.1 in Apache 2 allows remote attackers to execute arbitrary code via a server side script that sends a large amount of data.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1209

    Last Modified: 16 Apr 2026

    The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1210

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1211

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp for MaxWebPortal 1.30 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the Search parameter.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1219

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3 allows remote attackers to inject arbitrary web script or HTML via the osCsid parameter.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1220

    Last Modified: 16 Apr 2026

    BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1221

    Last Modified: 16 Apr 2026

    BEA WebLogic Express and Server 7.0 through 8.1 SP 1, under certain circumstances when a request to use T3 over SSL (t3s) is made to the insecure T3 port, may use a non-SSL connection for the communication, which could allow attackers to sniff sessions.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1226

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1228

    Last Modified: 16 Apr 2026

    Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1225

    Last Modified: 16 Apr 2026

    The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.

    Published: 31 Dec 2003
    3.6
    Low

    CVE-2003-1234

    Last Modified: 16 Apr 2026

    Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to fdrop.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1235

    Last Modified: 16 Apr 2026

    BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and the current working directory.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1236

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1237

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1403

    Last Modified: 16 Apr 2026

    foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1242

    Last Modified: 16 Apr 2026

    Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1243

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in Sage 1.0 b3 allows remote attackers to insert arbitrary HTML or web script via the mod parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1244

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1245

    Last Modified: 16 Apr 2026

    index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1246

    Last Modified: 16 Apr 2026

    NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1251

    Last Modified: 16 Apr 2026

    The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via a c_path that references a URL on a remote web server that contains the code.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1253

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to (1) dbase.php, (2) config.php, or (3) common.load.php.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1254

    Last Modified: 16 Apr 2026

    Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1261

    Last Modified: 16 Apr 2026

    Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1263

    Last Modified: 16 Apr 2026

    ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly due to an invalid method name.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1265

    Last Modified: 16 Apr 2026

    Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.

    Published: 31 Dec 2003