CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2003-1266

    Last Modified: 16 Apr 2026

    The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1273

    Last Modified: 16 Apr 2026

    Winamp 3.0 allows remote attackers to cause a denial of service (crash) via a .b4s file with a playlist name that contains some non-English characters, e.g. Cyrillic characters.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1274

    Last Modified: 16 Apr 2026

    Winamp 3.0 allows remote attackers to cause a denial of service (crash) via .b4s file with a file: argument to the Playstring parameter that contains MS-DOS device names such as aux.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1275

    Last Modified: 16 Apr 2026

    Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript function that uses the object.innerHTML function to recursively call that function.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1280

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1283

    Last Modified: 16 Apr 2026

    KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1284

    Last Modified: 16 Apr 2026

    Sambar Server before 6.0 beta 6 allows remote attackers to obtain sensitive information via direct requests to the default scripts (1) environ.pl and (2) testcgi.exe.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1286

    Last Modified: 16 Apr 2026

    HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attackers to send proxy HTTP requests to the Sambar Server's administrative interface and external web servers, by making a "Connection: keep-alive" request before the proxy requests.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1292

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1295

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1296

    Last Modified: 16 Apr 2026

    Easy File Sharing (EFS) Web Server 1.2 allows remote authenticated users to cause a denial of service via (1) an "empty symbol" in the Title field or (2) certain data in the Your Message field, possibly a long argument.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1291

    Last Modified: 16 Apr 2026

    VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1300

    Last Modified: 16 Apr 2026

    Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which triggers an access violation.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1301

    Last Modified: 16 Apr 2026

    Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1304

    Last Modified: 16 Apr 2026

    EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information via a direct request.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1310

    Last Modified: 16 Apr 2026

    The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack").

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1312

    Last Modified: 16 Apr 2026

    siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder places a session ID string in the value of the SMSESSION parameter in a URL, which might allow remote attackers to obtain the ID by sniffing, reading Referer logs, or other methods.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1313

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php.

    Published: 31 Dec 2003
    5.1
    Medium

    CVE-2003-1320

    Last Modified: 16 Apr 2026

    SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1321

    Last Modified: 16 Apr 2026

    Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1322

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1330

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.

    Published: 31 Dec 2003
    4
    Medium

    CVE-2003-1331

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.

    Published: 31 Dec 2003
    9.3
    Critical

    CVE-2003-1336

    Last Modified: 16 Apr 2026

    Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1338

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to inject arbitrary HTTP headers and possibly conduct HTTP Response Splitting attacks via CRLF sequences in the Location header.

    Published: 31 Dec 2003
    6.3
    Medium

    CVE-2003-1471

    Last Modified: 16 Apr 2026

    MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1335

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.5 allows remote attackers to download files from locations above the snif directory.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1343

    Last Modified: 16 Apr 2026

    Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.exe, which allows remote attackers to gain access to the web management interface via the vcc parameter, possibly "3560121183d3".

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1344

    Last Modified: 16 Apr 2026

    Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive information via a URL request for getservers.exe with the action parameter set to "selects1", which returns log files.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1345

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1346

    Last Modified: 16 Apr 2026

    D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware using AirPlus Access Point Manager.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1356

    Last Modified: 16 Apr 2026

    The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1358

    Last Modified: 16 Apr 2026

    rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1359

    Last Modified: 16 Apr 2026

    Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1360

    Last Modified: 16 Apr 2026

    Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1361

    Last Modified: 16 Apr 2026

    Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1412

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.

    Published: 31 Dec 2003
    4.8
    Medium

    CVE-2003-1428

    Last Modified: 16 Apr 2026

    Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1430

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1432

    Last Modified: 16 Apr 2026

    Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1456

    Last Modified: 16 Apr 2026

    Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1464

    Last Modified: 16 Apr 2026

    Buffer overflow in Siemens 45 series mobile phones allows remote attackers to cause a denial of service (disconnect and unavailable inbox) via a Short Message Service (SMS) message with a long image name.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1465

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in download.php in Phorum 3.4 through 3.4.2 allows remote attackers to read arbitrary files.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1467

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1487

    Last Modified: 16 Apr 2026

    Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1) UserAdmin program, (2) Edit user profile, or (3) stats program.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1489

    Last Modified: 16 Apr 2026

    upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1495

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1499

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder parameter.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1500

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix parameter.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1506

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.

    Published: 31 Dec 2003