CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2003-1152

    Last Modified: 16 Apr 2026

    WebTide 7.04 allows remote attackers to list arbitrary directories via an HTTP request for %3f.jsp (encoded "?").

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1157

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1179

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1212

    Last Modified: 16 Apr 2026

    MaxWebPortal 1.30 allows remote attackers to perform unauthorized actions by modifying hidden form fields, such as the (1) news, (2) lock, or (3) allmem fields in the 'start new topic' HTML page.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1223

    Last Modified: 16 Apr 2026

    The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1227

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1229

    Last Modified: 16 Apr 2026

    X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.

    Published: 31 Dec 2003
    5.1
    Medium

    CVE-2003-1232

    Last Modified: 16 Apr 2026

    Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.

    Published: 31 Dec 2003
    9.8
    Critical

    CVE-2003-1233

    Last Modified: 16 Apr 2026

    Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst command.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1240

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1249

    Last Modified: 16 Apr 2026

    WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1252

    Last Modified: 16 Apr 2026

    register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)" E-mail address with a "any_name.php" username.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1255

    Last Modified: 16 Apr 2026

    add_bookmark.php in Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to add arbitrary bookmarks as other users using a modified auth_user_id parameter.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1259

    Last Modified: 16 Apr 2026

    Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

    Published: 31 Dec 2003
    7.6
    High

    CVE-2003-1260

    Last Modified: 16 Apr 2026

    Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1271

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script.

    Published: 31 Dec 2003
    9.3
    Critical

    CVE-2003-1272

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Winamp 3.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .b4s file containing (1) a long playlist name or (2) a long path in a file: argument to the Playstring parameter.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1276

    Last Modified: 16 Apr 2026

    Netfone.exe of NetTelephone 3.5.6 uses weak encryption for user PIN's and stores user account numbers in plaintext in the HKEY_CURRENT_USER\Software\MediaRing.com\SDK\NetTelephone\settings registry key, which could allow local users to gain unauthorized access to NetTelephone accounts.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1277

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1279

    Last Modified: 16 Apr 2026

    S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6) /tmp/sgml2html$$tmp /tmp/sgml2html$$tmp1 /tmp/sgml2html$$tmp2 by sglm2html.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1282

    Last Modified: 16 Apr 2026

    IBM Net.Data allows remote attackers to obtain sensitive information such as path names, server names and possibly user names and passwords by causing the (1) $(DTW_CURRENT_FILENAME), (2) $(DATABASE), (3) $(LOGIN), (4) $(PASSWORD), and possibly other predefined variables that can be echoed back to the user via a web form.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1285

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server before 6.0 beta 6 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) isapi/testisa.dll, (2) testcgi.exe, (3) environ.pl, (4) the query parameter to samples/search.dll, (5) the price parameter to mortgage.pl, (6) the query string in dumpenv.pl, (7) the query string to dumpenv.pl, and (8) the E-Mail field of the guestbook script (book.pl).

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1287

    Last Modified: 16 Apr 2026

    Sambar Server before 6.0 beta 3 allows attackers with physical access to execute arbitrary code via a request with an MS-DOS device name such as com1.pl, con.pl, or aux.pl, which causes Perl to read the code from the associated device.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1288

    Last Modified: 16 Apr 2026

    Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (2) ip_info data structures and the (a) forget_original_parent, (b) goodness, (c) schedule, (d) update_process_times, and (e) vc_new_s_context functions.

    Published: 31 Dec 2003
    4
    Medium

    CVE-2003-1299

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1307

    Last Modified: 16 Apr 2026

    The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has disputed this vulnerability, saying "The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1308

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1309

    Last Modified: 16 Apr 2026

    The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain privileges via certain signals (aka "Device Driver Attack").

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1311

    Last Modified: 16 Apr 2026

    siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might trick users into visiting an arbitrary web site referenced by this parameter.

    Published: 31 Dec 2003
    7.8
    High

    CVE-2003-1318

    Last Modified: 16 Apr 2026

    Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.

    Published: 31 Dec 2003
    7.6
    High

    CVE-2003-1319

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-1323

    Last Modified: 16 Apr 2026

    Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group via unspecified vectors.

    Published: 31 Dec 2003
    4.6
    Medium

    CVE-2003-1324

    Last Modified: 16 Apr 2026

    Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.

    Published: 31 Dec 2003
    9.3
    Critical

    CVE-2003-1327

    Last Modified: 16 Apr 2026

    Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs a notification message to the administrator.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1334

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1337

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 31 Dec 2003
    10
    Critical

    CVE-2003-1339

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare allows remote attackers to cause a denial of service (crash) or execute arbitrary code, as demonstrated via (1) a long GET request and (2) a long operation or autologin parameter to SwEzModule.dll.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1342

    Last Modified: 16 Apr 2026

    Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memory consumption) in IIS via multiple URL requests for ActiveSupport.exe.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1347

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to comment.php, (2) uid parameter to profiles.php, (3) uid to users.php, and (4) homepage field.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1352

    Last Modified: 16 Apr 2026

    Gabber 0.8.7 sends an email to a specific address during user login and logout, which allows remote attackers to obtain user session activity and Gabber version number by sniffing.

    Published: 31 Dec 2003
    4.3
    Medium

    CVE-2003-1353

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Outreach Project Tool (OPT) 0.946b allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the news field.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1363

    Last Modified: 16 Apr 2026

    The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.

    Published: 31 Dec 2003
    8.5
    High

    CVE-2003-1364

    Last Modified: 16 Apr 2026

    Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1365

    Last Modified: 16 Apr 2026

    The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary commands, in shell scripts that rely on CGI::Lite to filter such dangerous inputs.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1380

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.

    Published: 31 Dec 2003
    6.4
    Medium

    CVE-2003-1386

    Last Modified: 16 Apr 2026

    AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1404

    Last Modified: 16 Apr 2026

    DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.

    Published: 31 Dec 2003
    5
    Medium

    CVE-2003-1408

    Last Modified: 16 Apr 2026

    Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.

    Published: 31 Dec 2003
    7.5
    High

    CVE-2003-1332

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.

    Published: 31 Dec 2003
    6.8
    Medium

    CVE-2003-0965

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.

    Published: 31 Dec 2003