CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2003-1509

    Last Modified: 16 Apr 2026

    Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file before the temp file is executed by the default web browser.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1512

    Last Modified: 16 Apr 2026

    Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1517

    Last Modified: 16 Apr 2026

    cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1519

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1528

    Last Modified: 16 Apr 2026

    nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1530

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the mark[] parameter.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1546

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section.

    Published: 31 Dec 2003
    4
    Medium

    CVE-2003-1563

    Last Modified: 16 Apr 2026

    Sun Cluster 2.2 through 3.2 for Oracle Parallel Server / Real Application Clusters (OPS/RAC) allows local users to cause a denial of service (cluster node panic or abort) by launching a daemon listening on a TCP port that would otherwise be used by the Distributed Lock Manager (DLM), possibly involving this daemon responding in a manner that spoofs a cluster reconfiguration.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-0954

    Last Modified: 16 Apr 2026

    Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1289

    Last Modified: 16 Apr 2026

    The iBCS2 system call translator for statfs in NetBSD 1.5 through 1.5.3 and FreeBSD 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1 allows local users to read portions of kernel memory (memory disclosure) via a large length parameter, which copies additional kernel memory into userland memory.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1389

    Last Modified: 16 Apr 2026

    RTS CryptoBuddy 1.2 and earlier truncates long passphrases without warning the user, which may make it easier to conduct certain brute force guessing attacks.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1485

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1488

    Last Modified: 16 Apr 2026

    The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.

    Published: 31 Dec 2003
    Unknown

    CVE-2003-1130

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-1071. Reason: This candidate is a duplicate of CVE-2003-1071. Notes: All CVE users should reference CVE-2003-1071 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-0857

    Last Modified: 16 Apr 2026

    The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1005

    Last Modified: 16 Apr 2026

    The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1066

    Last Modified: 16 Apr 2026

    Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long syslog UDP packets.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1409

    Last Modified: 16 Apr 2026

    TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1247

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.

    Published: 31 Dec 2003
    Unknown

    CVE-2003-0351

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0306. Reason: This candidate is a reservation duplicate of CVE-2003-0306. Notes: All CVE users should reference CVE-2003-0306 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-0363

    Last Modified: 16 Apr 2026

    Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.

    Published: 31 Dec 2003
    Unknown

    CVE-2003-0463

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-0627

    Last Modified: 16 Apr 2026

    psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername arguments.

    Published: 31 Dec 2003
    Unknown

    CVE-2003-0691

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not associated with any specific security issue. Notes: none

    Published: 31 Dec 2003
    Unknown

    CVE-2003-0698

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0743. Reason: This candidate is a duplicate of CVE-2003-0743. Notes: All CVE users should reference CVE-2003-0743 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-0900

    Last Modified: 16 Apr 2026

    Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.

    Published: 31 Dec 2003
    2.6
    Low

    CVE-2003-0956

    Last Modified: 16 Apr 2026

    Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to be returned from the disk when handling sparse files, or cause incorrect data to be returned when a file is truncated as it is being read, which might allow local users to obtain sensitive data that was originally owned by other users, a different vulnerability than CVE-2003-0018.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1085

    Last Modified: 16 Apr 2026

    The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, possibly caused by a buffer overflow.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1096

    Last Modified: 16 Apr 2026

    The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1109

    Last Modified: 16 Apr 2026

    The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1121

    Last Modified: 16 Apr 2026

    Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1132

    Last Modified: 16 Apr 2026

    The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1168

    Last Modified: 16 Apr 2026

    HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1169

    Last Modified: 16 Apr 2026

    DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1170

    Last Modified: 16 Apr 2026

    Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specifiers in command line arguments.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1178

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1180

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Advanced Poll 2.0.2 allows remote attackers to read arbitrary files or inject arbitrary local PHP files via .. sequences in the base_path or pollvars[lang] parameters to the admin files (1) index.php, (2) admin_tpl_new.php, (3) admin_tpl_misc_new.php, (4) admin_templates_misc.php, (5) admin_templates.php, (6) admin_stats.php, (7) admin_settings.php, (8) admin_preview.php, (9) admin_password.php, (10) admin_logout.php, (11) admin_license.php, (12) admin_help.php, (13) admin_embed.php, (14) admin_edit.php, or (15) admin_comment.php.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1204

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.12 BETA and earlier allow remote attackers to execute script on other clients via (1) the link parameter in sectionswindow.php, the directory parameter in (2) gallery.php, (3) navigation.php, or (4) uploadimage.php, the path parameter in (5) view.php, (6) the choice parameter in upload.php, (7) the sitename parameter in mambosimple.php, (8) the type parameter in upload.php, or the id parameter in (9) emailarticle.php, (10) emailfaq.php, or (11) emailnews.php.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1224

    Last Modified: 16 Apr 2026

    Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1231

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 5.5 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1239

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in sendphoto.php in WihPhoto 0.86 allows remote attackers to read arbitrary files via .. specifiers in the album parameter, and the target filename in the pic parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1248

    Last Modified: 16 Apr 2026

    H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1250

    Last Modified: 16 Apr 2026

    Efficient Networks 5861 DSL router, when running firmware 5.3.80 configured to block incoming TCP SYN, packets allows remote attackers to cause a denial of service (crash) via a flood of TCP SYN packets to the WAN interface using a port scanner such as nmap.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1262

    Last Modified: 16 Apr 2026

    Buffer overflow in the http_fetch function of HTTP Fetcher 1.0.0 and 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request via a long (1) host, (2) referer, or (3) userAgent value.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1264

    Last Modified: 16 Apr 2026

    TFTP server in Longshine Wireless Access Point (WAP) LCS-883R-AC-B, and in D-Link DI-614+ 2.0 which is based on it, allows remote attackers to obtain the WEP secret and gain administrator privileges by downloading the configuration file (config.img) and other files without authentication.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1269

    Last Modified: 16 Apr 2026

    AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1270

    Last Modified: 16 Apr 2026

    AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerability.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1278

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1281

    Last Modified: 16 Apr 2026

    cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1290

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI).

    Published: 31 Dec 2003