CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2003-0725

    Last Modified: 16 Apr 2026

    Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.

    Published: 3 Sept 2003
    7.5
    High

    CVE-2003-0723

    Last Modified: 16 Apr 2026

    Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.

    Published: 3 Sept 2003
    5
    Medium

    CVE-2003-0658

    Last Modified: 16 Apr 2026

    Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.

    Published: 3 Sept 2003
    7.5
    High

    CVE-2003-0729

    Last Modified: 16 Apr 2026

    Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.

    Published: 3 Sept 2003
    6.4
    Medium

    CVE-2003-0728

    Last Modified: 16 Apr 2026

    Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.

    Published: 3 Sept 2003
    2.1
    Low

    CVE-2003-0727

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.

    Published: 3 Sept 2003
    5
    Medium

    CVE-2003-0702

    Last Modified: 16 Apr 2026

    Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code in Internet Information Server (IIS) via a certain URL through SSL.

    Published: 3 Sept 2003
    7.5
    High

    CVE-2003-0707

    Last Modified: 16 Apr 2026

    Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.

    Published: 3 Sept 2003
    7.5
    High

    CVE-2003-0708

    Last Modified: 16 Apr 2026

    Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.

    Published: 3 Sept 2003
    7.5
    High

    CVE-2003-0709

    Last Modified: 16 Apr 2026

    Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command line option.

    Published: 3 Sept 2003
    7.5
    High

    CVE-2003-0724

    Last Modified: 16 Apr 2026

    ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain privileges.

    Published: 3 Sept 2003
    4.6
    Medium

    CVE-2003-0740

    Last Modified: 16 Apr 2026

    Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.

    Published: 3 Sept 2003
    7.5
    High

    CVE-2003-0730

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.

    Published: 30 Aug 2003
    7.5
    High

    CVE-2003-0686

    Last Modified: 16 Apr 2026

    Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.

    Published: 26 Aug 2003
    5
    Medium

    CVE-2003-0688

    Last Modified: 16 Apr 2026

    The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.

    Published: 25 Aug 2003
    7.5
    High

    CVE-2003-0901

    Last Modified: 16 Apr 2026

    Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.

    Published: 24 Aug 2003
    7.5
    High

    CVE-2003-0530

    Last Modified: 16 Apr 2026

    Buffer overflow in the BR549.DLL ActiveX control for Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to execute arbitrary code.

    Published: 22 Aug 2003
    7.5
    High

    CVE-2003-0531

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Zone" vulnerability.

    Published: 22 Aug 2003
    7.5
    High

    CVE-2003-0532

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 SP3 through 6.0 SP1 does not properly determine object types that are returned by web servers, which could allow remote attackers to execute arbitrary code via an object tag with a data parameter to a malicious file hosted on a server that returns an unsafe Content-Type, aka the "Object Type" vulnerability.

    Published: 22 Aug 2003
    7.5
    High

    CVE-2003-0701

    Last Modified: 16 Apr 2026

    Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.

    Published: 22 Aug 2003
    7.5
    High

    CVE-2003-0353

    Last Modified: 16 Apr 2026

    Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.

    Published: 21 Aug 2003
    7.5
    High

    CVE-2003-0654

    Last Modified: 16 Apr 2026

    Buffer overflow in autorespond may allow remote attackers to execute arbitrary code as the autorespond user via qmail.

    Published: 21 Aug 2003
    7.5
    High

    CVE-2003-0699

    Last Modified: 16 Apr 2026

    The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.

    Published: 21 Aug 2003
    7.5
    High

    CVE-2003-1063

    Last Modified: 16 Apr 2026

    The patches (1) 105693-13, (2) 108800-02, (3) 105694-13, and (4) 108801-02 for cachefs on Solaris 2.6 and 7 overwrite the inetd.conf file, which may silently reenable services and allow remote attackers to bypass the intended security policy.

    Published: 20 Aug 2003
    2.1
    Low

    CVE-2003-0547

    Last Modified: 16 Apr 2026

    GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.

    Published: 20 Aug 2003
    5
    Medium

    CVE-2003-0548

    Last Modified: 16 Apr 2026

    The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.

    Published: 20 Aug 2003
    5
    Medium

    CVE-2003-0549

    Last Modified: 16 Apr 2026

    The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.

    Published: 20 Aug 2003
    10
    Critical

    CVE-2003-1202

    Last Modified: 16 Apr 2026

    The checklogin function in omail.pl for omail webmail 0.98.4 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a (1) password, (2) domainname, or (3) username.

    Published: 19 Aug 2003
    7.2
    High

    CVE-2003-0584

    Last Modified: 16 Apr 2026

    Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.

    Published: 18 Aug 2003
    5
    Medium

    CVE-2003-0176

    Last Modified: 16 Apr 2026

    The Name Service Daemon (nsd), when running on an NIS master on SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via a UDP port scan.

    Published: 18 Aug 2003
    5
    Medium

    CVE-2003-0572

    Last Modified: 16 Apr 2026

    Unknown vulnerability in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, allows attackers to cause a denial of service (memory consumption).

    Published: 18 Aug 2003
    5
    Medium

    CVE-2003-0573

    Last Modified: 16 Apr 2026

    The DNS callbacks in nsd in SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, do not perform sufficient sanity checking, with unknown impact.

    Published: 18 Aug 2003
    6.9
    Medium

    CVE-2003-0587

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.x allows remote authenticated users to execute arbitrary web script and gain administrative access via the "displayed name" attribute of the "ubber" cookie.

    Published: 18 Aug 2003
    10
    Critical

    CVE-2003-0588

    Last Modified: 16 Apr 2026

    admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.

    Published: 18 Aug 2003
    10
    Critical

    CVE-2003-0589

    Last Modified: 16 Apr 2026

    admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.

    Published: 18 Aug 2003
    7.1
    High

    CVE-2003-0590

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.

    Published: 18 Aug 2003
    4.6
    Medium

    CVE-2003-0177

    Last Modified: 16 Apr 2026

    SGI IRIX 6.5.x through 6.5.20f, and possibly earlier versions, does not follow "-" entries in the /etc/group file, which may cause subsequent group membership entries to be processed inadvertently.

    Published: 18 Aug 2003
    7.2
    High

    CVE-2003-0574

    Last Modified: 16 Apr 2026

    Unknown vulnerability in SGI IRIX 6.5.x through 6.5.20, and possibly earlier versions, allows local users to cause a core dump in scheme and possibly gain privileges via certain environment variables, a different vulnerability than CVE-2001-0797 and CVE-1999-0028.

    Published: 18 Aug 2003
    7.2
    High

    CVE-2003-0583

    Last Modified: 16 Apr 2026

    Buffer overflow in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via a long command line argument.

    Published: 18 Aug 2003
    7.5
    High

    CVE-2003-0585

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp of Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to bypass authentication and execute arbitrary SQL code via the (1) user or (2) pass parameters.

    Published: 18 Aug 2003
    7.5
    High

    CVE-2003-0586

    Last Modified: 16 Apr 2026

    Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.

    Published: 18 Aug 2003
    5
    Medium

    CVE-2003-0576

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the NFS daemon (nfsd) in SGI IRIX 6.5.19f and earlier allows remote attackers to cause a denial of service (kernel panic) via certain packets that cause XDR decoding errors, a different vulnerability than CVE-2003-0619.

    Published: 15 Aug 2003
    2.1
    Low

    CVE-2003-0679

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allows local users to truncate or overwrite certain files.

    Published: 15 Aug 2003
    5
    Medium

    CVE-2002-1566

    Last Modified: 16 Apr 2026

    netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to cause a denial of service (crash) via a long string to port 9284.

    Published: 15 Aug 2003
    7.5
    High

    CVE-2003-0685

    Last Modified: 16 Apr 2026

    Buffer overflow in Netris 0.52 and earlier, and possibly other versions, allows remote malicious Netris servers to execute arbitrary code on netris clients via a long server response.

    Published: 15 Aug 2003
    Unknown

    CVE-2003-0598

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0657. Reason: This candidate is a reservation duplicate of CVE-2003-0657. Notes: All CVE users should reference CVE-2003-0657 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Aug 2003
    4.6
    Medium

    CVE-2003-0613

    Last Modified: 16 Apr 2026

    Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlier allows local users to execute arbitrary code via the high score file.

    Published: 14 Aug 2003
    4.6
    Medium

    CVE-2003-0645

    Last Modified: 16 Apr 2026

    man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.

    Published: 14 Aug 2003
    7.2
    High

    CVE-2003-0649

    Last Modified: 16 Apr 2026

    Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.

    Published: 14 Aug 2003
    2.1
    Low

    CVE-2003-0656

    Last Modified: 16 Apr 2026

    eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.

    Published: 14 Aug 2003