CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2003-0301

    Last Modified: 16 Apr 2026

    The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.

    Published: 15 May 2003
    5.1
    Medium

    CVE-2003-0275

    Last Modified: 16 Apr 2026

    SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.

    Published: 14 May 2003
    5
    Medium

    CVE-2003-0277

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.

    Published: 14 May 2003
    6.8
    Medium

    CVE-2003-0278

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

    Published: 14 May 2003
    4.6
    Medium

    CVE-2003-0281

    Last Modified: 16 Apr 2026

    Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.

    Published: 14 May 2003
    6.8
    Medium

    CVE-2003-0283

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

    Published: 14 May 2003
    5
    Medium

    CVE-2003-0285

    Last Modified: 16 Apr 2026

    IBM AIX 5.2 and earlier distributes Sendmail with a configuration file (sendmail.cf) with the (1) promiscuous_relay, (2) accept_unresolvable_domains, and (3) accept_unqualified_senders features enabled, which allows Sendmail to be used as an open mail relay for sending spam e-mail.

    Published: 14 May 2003
    6.8
    Medium

    CVE-2003-0287

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Movable Type before 2.6, and possibly other versions including 2.63, allows remote attackers to insert arbitrary web script or HTML via the Name textbox, possibly when the "Allow HTML in comments?" option is enabled.

    Published: 14 May 2003
    7.2
    High

    CVE-2003-0289

    Last Modified: 16 Apr 2026

    Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

    Published: 14 May 2003
    6.8
    Medium

    CVE-2003-0217

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Neoteris Instant Virtual Extranet (IVE) 3.01 and earlier allows remote attackers to insert arbitrary web script and bypass authentication via a certain CGI script.

    Published: 14 May 2003
    7.6
    High

    CVE-2003-0270

    Last Modified: 16 Apr 2026

    The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.

    Published: 14 May 2003
    5
    Medium

    CVE-2003-0276

    Last Modified: 16 Apr 2026

    Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.

    Published: 14 May 2003
    2.6
    Low

    CVE-2003-0279

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.

    Published: 14 May 2003
    10
    Critical

    CVE-2003-0280

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.

    Published: 14 May 2003
    7.5
    High

    CVE-2003-0284

    Last Modified: 16 Apr 2026

    Adobe Acrobat 5 does not properly validate JavaScript in PDF files, which allows remote attackers to write arbitrary files into the Plug-ins folder that spread to other PDF documents, as demonstrated by the W32.Yourde virus.

    Published: 14 May 2003
    7.5
    High

    CVE-2003-0286

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.

    Published: 14 May 2003
    10
    Critical

    CVE-2003-0288

    Last Modified: 16 Apr 2026

    Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.

    Published: 14 May 2003
    5
    Medium

    CVE-2003-0290

    Last Modified: 16 Apr 2026

    Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.

    Published: 14 May 2003
    7.5
    High

    CVE-2003-0297

    Last Modified: 16 Apr 2026

    c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.

    Published: 14 May 2003
    5
    Medium

    CVE-2003-0187

    Last Modified: 16 Apr 2026

    The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.

    Published: 14 May 2003
    3.6
    Low

    CVE-2003-0246

    Last Modified: 16 Apr 2026

    The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.

    Published: 12 May 2003
    6.8
    Medium

    CVE-2003-1146

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

    Published: 11 May 2003
    4.3
    Medium

    CVE-2003-0442

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

    Published: 11 May 2003
    2.1
    Low

    CVE-2003-0334

    Last Modified: 16 Apr 2026

    BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mode changes that are not properly handled in names.c.

    Published: 10 May 2003
    7.5
    High

    CVE-2003-0243

    Last Modified: 16 Apr 2026

    Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.

    Published: 9 May 2003
    7.5
    High

    CVE-2003-0256

    Last Modified: 16 Apr 2026

    The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.

    Published: 9 May 2003
    7.5
    High

    CVE-2003-0271

    Last Modified: 16 Apr 2026

    Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.

    Published: 9 May 2003
    6.8
    Medium

    CVE-2003-0273

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web interface for Request Tracker (RT) 1.0 through 1.0.7 allows remote attackers to execute script via message bodies.

    Published: 9 May 2003
    10
    Critical

    CVE-2003-0274

    Last Modified: 16 Apr 2026

    Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.

    Published: 9 May 2003
    10
    Critical

    CVE-2003-0272

    Last Modified: 16 Apr 2026

    admin.php in miniPortail allows remote attackers to gain administrative privileges by setting the miniPortailAdmin cookie to an "adminok" value.

    Published: 9 May 2003
    2.6
    Low

    CVE-2003-0282

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.

    Published: 9 May 2003
    7.5
    High

    CVE-2003-0228

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.

    Published: 8 May 2003
    5
    Medium

    CVE-2003-0259

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.

    Published: 8 May 2003
    4.6
    Medium

    CVE-2003-0261

    Last Modified: 16 Apr 2026

    fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges.

    Published: 8 May 2003
    7.2
    High

    CVE-2003-0262

    Last Modified: 16 Apr 2026

    leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.

    Published: 8 May 2003
    7.5
    High

    CVE-2003-0263

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.

    Published: 8 May 2003
    6.2
    Medium

    CVE-2003-0265

    Last Modified: 16 Apr 2026

    Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.

    Published: 8 May 2003
    7.5
    High

    CVE-2003-0266

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in SLWebMail 3 on Windows systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long Language parameter to showlogin.dll, (2) a long CompanyID parameter to recman.dll, (3) a long CompanyID parameter to admin.dll, or (4) a long CompanyID parameter to globallogin.dll.

    Published: 8 May 2003
    5
    Medium

    CVE-2003-0267

    Last Modified: 16 Apr 2026

    ShowGodLog.dll in SLWebMail 3 on Windows systems allows remote attackers to read arbitrary files by directly calling ShowGodLog.dll with an argument specifying the full path of the target file.

    Published: 8 May 2003
    7.2
    High

    CVE-2003-0269

    Last Modified: 16 Apr 2026

    Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.

    Published: 8 May 2003
    7.5
    High

    CVE-2003-0258

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.

    Published: 8 May 2003
    5
    Medium

    CVE-2003-0260

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.

    Published: 8 May 2003
    7.5
    High

    CVE-2003-0264

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.

    Published: 8 May 2003
    5
    Medium

    CVE-2003-0268

    Last Modified: 16 Apr 2026

    SLWebMail 3 on Windows systems allows remote attackers to identify the full path of the server via invalid requests to DLLs such as WebMailReq.dll, which reveals the path in an error message.

    Published: 8 May 2003
    7.5
    High

    CVE-2003-0236

    Last Modified: 16 Apr 2026

    Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.

    Published: 7 May 2003
    7.5
    High

    CVE-2003-0235

    Last Modified: 16 Apr 2026

    Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.

    Published: 7 May 2003
    7.5
    High

    CVE-2003-0237

    Last Modified: 16 Apr 2026

    The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.

    Published: 7 May 2003
    5
    Medium

    CVE-2003-0238

    Last Modified: 16 Apr 2026

    The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.

    Published: 7 May 2003
    5
    Medium

    CVE-2003-0239

    Last Modified: 16 Apr 2026

    icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.

    Published: 7 May 2003
    4.6
    Medium

    CVE-2003-0194

    Last Modified: 16 Apr 2026

    tcpdump does not properly drop privileges to the pcap user when starting up.

    Published: 5 May 2003