CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2003-0848

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.

    Published: 6 Oct 2003
    7.5
    High

    CVE-2003-0845

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.

    Published: 5 Oct 2003
    4.6
    Medium

    CVE-2003-1053

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in XShisen allow attackers to execute arbitrary code via a long (1) -KCONV command line option or (2) XSHISENLIB environment variable.

    Published: 3 Oct 2003
    5
    Medium

    CVE-2002-1568

    Last Modified: 16 Apr 2026

    OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c.

    Published: 2 Oct 2003
    7.5
    High

    CVE-2003-0835

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.

    Published: 1 Oct 2003
    5
    Medium

    CVE-2003-0832

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header.

    Published: 1 Oct 2003
    Unknown

    CVE-2003-0964

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: N/A. Notes: none

    Published: 1 Oct 2003
    7.5
    High

    CVE-2003-0833

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname.

    Published: 1 Oct 2003
    4.6
    Medium

    CVE-2003-0830

    Last Modified: 16 Apr 2026

    Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.

    Published: 1 Oct 2003
    5
    Medium

    CVE-2003-0543

    Last Modified: 16 Apr 2026

    Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.

    Published: 30 Sept 2003
    5
    Medium

    CVE-2003-0544

    Last Modified: 16 Apr 2026

    OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.

    Published: 30 Sept 2003
    9.8
    Critical

    CVE-2003-0545

    Last Modified: 16 Apr 2026

    Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.

    Published: 30 Sept 2003
    4.3
    Medium

    CVE-2003-0992

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.

    Published: 29 Sept 2003
    9
    Critical

    CVE-2003-0831

    Last Modified: 16 Apr 2026

    ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.

    Published: 25 Sept 2003
    5
    Medium

    CVE-2003-0804

    Last Modified: 16 Apr 2026

    The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.

    Published: 25 Sept 2003
    10
    Critical

    CVE-2003-0786

    Last Modified: 16 Apr 2026

    The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.

    Published: 25 Sept 2003
    7.5
    High

    CVE-2003-0787

    Last Modified: 16 Apr 2026

    The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain privileges.

    Published: 25 Sept 2003
    10
    Critical

    CVE-2003-0784

    Last Modified: 16 Apr 2026

    Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.

    Published: 23 Sept 2003
    5
    Medium

    CVE-2003-0827

    Last Modified: 16 Apr 2026

    The DB2 Discovery Service for IBM DB2 before FixPak 10a allows remote attackers to cause a denial of service (crash) via a long packet to UDP port 523.

    Published: 23 Sept 2003
    7.2
    High

    CVE-2003-0697

    Last Modified: 16 Apr 2026

    Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.

    Published: 23 Sept 2003
    7.5
    High

    CVE-2003-0785

    Last Modified: 16 Apr 2026

    ipmasq before 3.5.12, in certain configurations, may forward packets to the external interface even if the packets are not associated with an established connection, which could allow remote attackers to bypass intended filtering.

    Published: 23 Sept 2003
    7.2
    High

    CVE-2003-0783

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in hztty 2.0 allow local users to gain root privileges.

    Published: 23 Sept 2003
    7.5
    High

    CVE-2003-0826

    Last Modified: 16 Apr 2026

    lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.

    Published: 23 Sept 2003
    6.8
    Medium

    CVE-2002-1567

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

    Published: 19 Sept 2003
    7.2
    High

    CVE-2003-0742

    Last Modified: 16 Apr 2026

    SCO Internet Manager (mana) allows local users to execute arbitrary programs by setting the REMOTE_ADDR environment variable to cause menu.mana to run as if it were called from ncsa_httpd, then modifying the PATH environment variable to point to a malicious "hostname" program.

    Published: 19 Sept 2003
    7.5
    High

    CVE-2003-0805

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.

    Published: 19 Sept 2003
    7.2
    High

    CVE-2003-0758

    Last Modified: 16 Apr 2026

    Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.

    Published: 19 Sept 2003
    7.2
    High

    CVE-2003-0759

    Last Modified: 16 Apr 2026

    Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.

    Published: 19 Sept 2003
    7.5
    High

    CVE-2003-0680

    Last Modified: 16 Apr 2026

    Unknown vulnerability in NFS for SGI IRIX 6.5.21 and earlier may allow an NFS client to bypass read-only restrictions.

    Published: 18 Sept 2003
    4.3
    Medium

    CVE-2003-0801

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.

    Published: 18 Sept 2003
    5
    Medium

    CVE-2003-0802

    Last Modified: 16 Apr 2026

    Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).

    Published: 18 Sept 2003
    7.5
    High

    CVE-2003-0803

    Last Modified: 16 Apr 2026

    Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.

    Published: 18 Sept 2003
    10
    Critical

    CVE-2003-0722

    Last Modified: 16 Apr 2026

    The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.

    Published: 17 Sept 2003
    7.5
    High

    CVE-2003-0681

    Last Modified: 16 Apr 2026

    A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.

    Published: 17 Sept 2003
    10
    Critical

    CVE-2003-0694

    Last Modified: 16 Apr 2026

    The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

    Published: 17 Sept 2003
    7.5
    High

    CVE-2003-0682

    Last Modified: 16 Apr 2026

    "Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.

    Published: 16 Sept 2003
    10
    Critical

    CVE-2003-0690

    Last Modified: 16 Apr 2026

    KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.

    Published: 16 Sept 2003
    7.5
    High

    CVE-2003-0692

    Last Modified: 16 Apr 2026

    KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.

    Published: 16 Sept 2003
    7.5
    High

    CVE-2003-0695

    Last Modified: 16 Apr 2026

    Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.

    Published: 16 Sept 2003
    10
    Critical

    CVE-2003-0693

    Last Modified: 16 Apr 2026

    A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.

    Published: 15 Sept 2003
    7.5
    High

    CVE-2003-0779

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers to execute arbitrary SQL via a CallerID string.

    Published: 12 Sept 2003
    7.5
    High

    CVE-2003-0772

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.

    Published: 12 Sept 2003
    4.6
    Medium

    CVE-2003-0771

    Last Modified: 16 Apr 2026

    Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.

    Published: 12 Sept 2003
    7.5
    High

    CVE-2003-0770

    Last Modified: 16 Apr 2026

    FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.

    Published: 12 Sept 2003
    4.3
    Medium

    CVE-2003-0769

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.

    Published: 12 Sept 2003
    7.5
    High

    CVE-2003-0767

    Last Modified: 16 Apr 2026

    Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers to cause a denial of service and execute arbitrary code via a client request with a large length value.

    Published: 12 Sept 2003
    7.5
    High

    CVE-2003-0765

    Last Modified: 16 Apr 2026

    The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.

    Published: 12 Sept 2003
    4.3
    Medium

    CVE-2003-0763

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method parameter, as demonstrated using the PAGE parameter.

    Published: 12 Sept 2003
    7.5
    High

    CVE-2003-0761

    Last Modified: 16 Apr 2026

    Buffer overflow in the get_msg_text of chan_sip.c in the Session Initiation Protocol (SIP) protocol implementation for Asterisk releases before August 15, 2003, allows remote attackers to execute arbitrary code via certain (1) MESSAGE or (2) INFO requests.

    Published: 12 Sept 2003
    10
    Critical

    CVE-2003-0715

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.

    Published: 12 Sept 2003