CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2003-1293

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the guestbook.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1298

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with "./.." (dot slash dot dot).

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1316

    Last Modified: 16 Apr 2026

    mod.php in eNdonesia 8.2 allows remote attackers to obtain sensitive information via a ' (quote) value in the lng parameter, which reveals the path in an error message. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1317

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web script or HTML via the mod parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Dec 2003
    5.2
    Medium

    CVE-2003-1325

    Last Modified: 16 Apr 2026

    The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related issue to CVE-2006-0734.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1333

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1341

    Last Modified: 16 Apr 2026

    The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1354

    Last Modified: 16 Apr 2026

    Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1355

    Last Modified: 16 Apr 2026

    Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1370

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Nuked-Klan 1.2b allow remote attackers to inject arbitrary HTML or web script via (1) the Author field in the Guestbook module, (2) the Titre or Pseudo fields in the Forum module, or (3) "La Tribune Libre" in the Shoutbox module.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1371

    Last Modified: 16 Apr 2026

    Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1373

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL (%00) characters in CGI parameters, as demonstrated using the lang parameter in prefs.php.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1382

    Last Modified: 16 Apr 2026

    Buffer overflow in ISMail 1.4.3 and earlier allow remote attackers to execute arbitrary code via long domain names in (1) MAIL FROM or (2) RCPT TO fields.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1383

    Last Modified: 16 Apr 2026

    WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the MySQL database username and password.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1384

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PY-Livredor 1.0 allows remote attackers to insert arbitrary web script or HTML via the (1) titre, (2) Votre pseudo, (3) Votre e-mail, or (4) Votre message fields.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1385

    Last Modified: 16 Apr 2026

    ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1394

    Last Modified: 16 Apr 2026

    CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.

    Published: 31 Dec 2003
    9
    Critical

    CVE-2003-1395

    Last Modified: 16 Apr 2026

    Buffer overflow in KaZaA Media Desktop 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a response to the ad server.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1397

    Last Modified: 16 Apr 2026

    The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1400

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1407

    Last Modified: 16 Apr 2026

    Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.

    Published: 31 Dec 2003
    3.3
    Low

    CVE-2003-1426

    Last Modified: 16 Apr 2026

    Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1427

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1435

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.

    Published: 31 Dec 2003
    4.4
    Medium

    CVE-2003-1444

    Last Modified: 16 Apr 2026

    Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1455

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the launch_bcrelay function in pptpctrl.c in PoPToP 1.1.4-b1 through PoPToP 1.1.4-b3 allow local users to execute arbitrary code.

    Published: 31 Dec 2003
    3.5
    Low

    CVE-2003-1463

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1475

    Last Modified: 16 Apr 2026

    Netbus 1.5 through 1.7 allows more than one client to be connected at the same time, but only prompts the first connection for authentication, which allows remote attackers to gain access.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1496

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due to lack of details in the vendor advisory, it is not clear whether this is the same issue as CVE-1999-0840.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1507

    Last Modified: 16 Apr 2026

    Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1516

    Last Modified: 16 Apr 2026

    The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1518

    Last Modified: 16 Apr 2026

    Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1529

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Seagull Software Systems J Walk application server 3.2C9, and other versions before 3.3c4, allows remote attackers to read arbitrary files via a ".%252e" (encoded dot dot) in the URL.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1537

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1545

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1554

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in scozbook/add.php in ScozNet ScozBook 1.1 BETA allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) useremail, (3) aim, (4) msn, (5) sitename and (6) siteaddy variables.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-0249

    Last Modified: 16 Apr 2026

    PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, such as Apache httpd 2.0, as demonstrated using a Limit directive. NOTE: this issue has been disputed by the Apache security team, saying "It is by design that PHP allows scripts to process any request method. A script which does not explicitly verify the request method will hence be processed as normal for arbitrary methods. It is therefore expected behaviour that one cannot implement per-method access control using the Apache configuration alone, which is the assumption made in this report.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-0887

    Last Modified: 16 Apr 2026

    ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-0959

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the 32bit emulation for AMD64 architectures in Linux 2.4 kernel before 2.4.21 allows attackers to cause a denial of service or gain root privileges via unspecified vectors that trigger copy_from_user function calls with improper length arguments.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1076

    Last Modified: 16 Apr 2026

    Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a .forward file.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1087

    Last Modified: 16 Apr 2026

    Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows remote attackers to cause a denial of service (program failure) via certain network traffic.

    Published: 31 Dec 2003
    7.2
    High

    CVE-2003-1097

    Last Modified: 16 Apr 2026

    Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.

    Published: 31 Dec 2003
    2.6
    Low

    CVE-2003-1105

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1106

    Last Modified: 16 Apr 2026

    The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1110

    Last Modified: 16 Apr 2026

    The Session Initiation Protocol (SIP) implementation in Columbia SIP User Agent (sipc) 1.74 and other versions before sipc 2.0 build 2003-02-21 allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1112

    Last Modified: 16 Apr 2026

    The Session Initiation Protocol (SIP) implementation in Ingate Firewall and Ingate SIParator before 3.1.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1113

    Last Modified: 16 Apr 2026

    The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1114

    Last Modified: 16 Apr 2026

    The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways running SIPv2.4 and SIPv4.3 firmware allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1115

    Last Modified: 16 Apr 2026

    The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

    Published: 31 Dec 2003
    2.1
    Low

    CVE-2003-1122

    Last Modified: 16 Apr 2026

    ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.

    Published: 31 Dec 2003