CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2003-1185

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.

    Published: 3 Nov 2003
    6.8
    Medium

    CVE-2003-1182

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.

    Published: 3 Nov 2003
    4.3
    Medium

    CVE-2003-1184

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."

    Published: 3 Nov 2003
    7.5
    High

    CVE-2003-1196

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Published: 3 Nov 2003
    6.8
    Medium

    CVE-2003-1145

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.

    Published: 3 Nov 2003
    7.5
    High

    CVE-2003-0925

    Last Modified: 16 Apr 2026

    Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.

    Published: 3 Nov 2003
    7.5
    High

    CVE-2003-0927

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.

    Published: 3 Nov 2003
    5
    Medium

    CVE-2003-0926

    Last Modified: 16 Apr 2026

    Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.

    Published: 3 Nov 2003
    5
    Medium

    CVE-2003-0788

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).

    Published: 3 Nov 2003
    5
    Medium

    CVE-2003-1188

    Last Modified: 16 Apr 2026

    Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.

    Published: 2 Nov 2003
    6.8
    Medium

    CVE-2003-1187

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.

    Published: 2 Nov 2003
    5
    Medium

    CVE-2003-1159

    Last Modified: 16 Apr 2026

    Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.

    Published: 31 Oct 2003
    4.6
    Medium

    CVE-2003-0883

    Last Modified: 16 Apr 2026

    The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the system.

    Published: 30 Oct 2003
    6.8
    Medium

    CVE-2003-1197

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message parameter or (2) topic field of a new thread.

    Published: 30 Oct 2003
    10
    Critical

    CVE-2003-1160

    Last Modified: 16 Apr 2026

    FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).

    Published: 30 Oct 2003
    4.6
    Medium

    CVE-2003-0895

    Last Modified: 16 Apr 2026

    Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and possibly execute arbitrary code via a long command line argument (argv[]).

    Published: 30 Oct 2003
    5
    Medium

    CVE-2003-0882

    Last Modified: 16 Apr 2026

    Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.

    Published: 30 Oct 2003
    2.1
    Low

    CVE-2003-0876

    Last Modified: 16 Apr 2026

    Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), which could cause the directories to have less restrictive permissions than intended.

    Published: 30 Oct 2003
    9.8
    Critical

    CVE-2003-0899

    Last Modified: 16 Apr 2026

    Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.

    Published: 30 Oct 2003
    6.8
    Medium

    CVE-2003-1194

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.

    Published: 30 Oct 2003
    7.5
    High

    CVE-2003-0683

    Last Modified: 16 Apr 2026

    NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.

    Published: 30 Oct 2003
    7.5
    High

    CVE-2003-0871

    Last Modified: 16 Apr 2026

    Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."

    Published: 30 Oct 2003
    4.6
    Medium

    CVE-2003-0877

    Last Modified: 16 Apr 2026

    Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.

    Published: 30 Oct 2003
    7.5
    High

    CVE-2003-1143

    Last Modified: 16 Apr 2026

    Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.

    Published: 30 Oct 2003
    7.5
    High

    CVE-2002-1570

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variable data past the end of an array.

    Published: 30 Oct 2003
    2.1
    Low

    CVE-2003-0878

    Last Modified: 16 Apr 2026

    slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.

    Published: 30 Oct 2003
    4.6
    Medium

    CVE-2003-0880

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane in System Preferences.

    Published: 30 Oct 2003
    7.5
    High

    CVE-2003-0881

    Last Modified: 16 Apr 2026

    Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.

    Published: 30 Oct 2003
    5
    Medium

    CVE-2003-1191

    Last Modified: 16 Apr 2026

    chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from being loaded.

    Published: 29 Oct 2003
    5
    Medium

    CVE-2003-1189

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Nokia IPSO 3.7, configured as IP Clusters, allows remote attackers to cause a denial of service via unknown attack vectors.

    Published: 29 Oct 2003
    7.5
    High

    CVE-2003-1186

    Last Modified: 16 Apr 2026

    Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.

    Published: 29 Oct 2003
    7.2
    High

    CVE-2003-0542

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.

    Published: 29 Oct 2003
    4.6
    Medium

    CVE-2003-1183

    Last Modified: 16 Apr 2026

    The WebCache component in Oracle Files 9.0.3.1.0, 9.0.3.2.0, and 9.0.3.3.0 of Oracle Collaboration Suite Release 1 caches files despite the cacheability rules imposed by Oracle Files, which allows local users to gain access.

    Published: 28 Oct 2003
    Unknown

    CVE-2003-0879

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0518. Reason: This candidate is a reservation duplicate of CVE-2003-0518. Notes: All CVE users should reference CVE-2003-0518 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Oct 2003
    4.6
    Medium

    CVE-2003-0898

    Last Modified: 16 Apr 2026

    IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) db2job2.

    Published: 28 Oct 2003
    4.3
    Medium

    CVE-2003-1151

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.

    Published: 28 Oct 2003
    10
    Critical

    CVE-2003-0789

    Last Modified: 16 Apr 2026

    mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.

    Published: 28 Oct 2003
    10
    Critical

    CVE-2003-1140

    Last Modified: 16 Apr 2026

    Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.

    Published: 27 Oct 2003
    5
    Medium

    CVE-2003-1139

    Last Modified: 16 Apr 2026

    Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.

    Published: 27 Oct 2003
    5
    Medium

    CVE-2003-1137

    Last Modified: 16 Apr 2026

    Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

    Published: 27 Oct 2003
    5
    Medium

    CVE-2003-1138

    Last Modified: 16 Apr 2026

    The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).

    Published: 27 Oct 2003
    4.3
    Medium

    CVE-2003-1149

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked site, which is displayed on the blocked sites error page.

    Published: 27 Oct 2003
    7.5
    High

    CVE-2003-1150

    Last Modified: 16 Apr 2026

    Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.

    Published: 27 Oct 2003
    5
    Medium

    CVE-2003-1060

    Last Modified: 16 Apr 2026

    The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.

    Published: 27 Oct 2003
    7.5
    High

    CVE-2003-1148

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter to (1) config.inc.php or (2) new-visitor.inc.php in common/visiteurs/include/.

    Published: 25 Oct 2003
    7.5
    High

    CVE-2003-0896

    Last Modified: 16 Apr 2026

    The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.

    Published: 25 Oct 2003
    5
    Medium

    CVE-2003-0874

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.

    Published: 25 Oct 2003
    7.2
    High

    CVE-2001-1411

    Last Modified: 16 Apr 2026

    Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.

    Published: 25 Oct 2003
    2.1
    Low

    CVE-2001-1412

    Last Modified: 16 Apr 2026

    nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.

    Published: 25 Oct 2003
    7.5
    High

    CVE-2003-0850

    Last Modified: 16 Apr 2026

    The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."

    Published: 25 Oct 2003