CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2003-0255

    Last Modified: 16 Apr 2026

    The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.

    Published: 4 May 2003
    7.5
    High

    CVE-2003-0118

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.

    Published: 2 May 2003
    7.5
    High

    CVE-2003-0233

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.

    Published: 2 May 2003
    7.5
    High

    CVE-2003-0115

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.

    Published: 2 May 2003
    7.5
    High

    CVE-2003-0117

    Last Modified: 16 Apr 2026

    Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.

    Published: 2 May 2003
    7.6
    High

    CVE-2003-1562

    Last Modified: 16 Apr 2026

    sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.

    Published: 1 May 2003
    5
    Medium

    CVE-2003-0428

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.

    Published: 1 May 2003
    7.5
    High

    CVE-2003-0429

    Last Modified: 16 Apr 2026

    The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.

    Published: 1 May 2003
    5
    Medium

    CVE-2003-0430

    Last Modified: 16 Apr 2026

    The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.

    Published: 1 May 2003
    10
    Critical

    CVE-2003-0431

    Last Modified: 16 Apr 2026

    The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.

    Published: 1 May 2003
    10
    Critical

    CVE-2003-0432

    Last Modified: 16 Apr 2026

    Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.

    Published: 1 May 2003
    9.8
    Critical

    CVE-2003-0356

    Last Modified: 16 Apr 2026

    Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.

    Published: 1 May 2003
    7.5
    High

    CVE-2003-0357

    Last Modified: 16 Apr 2026

    Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.

    Published: 1 May 2003
    9
    Critical

    CVE-2003-0222

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.

    Published: 30 Apr 2003
    5
    Medium

    CVE-2003-0190

    Last Modified: 16 Apr 2026

    OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

    Published: 30 Apr 2003
    9.8
    Critical

    CVE-2003-0174

    Last Modified: 16 Apr 2026

    The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.

    Published: 29 Apr 2003
    7.5
    High

    CVE-2003-0218

    Last Modified: 16 Apr 2026

    Buffer overflow in PostMethod() function for Monkey HTTP Daemon (monkeyd) 0.6.1 and earlier allows remote attackers to execute arbitrary code via a POST request with a large body.

    Published: 29 Apr 2003
    7.5
    High

    CVE-2003-0219

    Last Modified: 16 Apr 2026

    Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.

    Published: 29 Apr 2003
    7.5
    High

    CVE-2003-0220

    Last Modified: 16 Apr 2026

    Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.

    Published: 29 Apr 2003
    7.2
    High

    CVE-2003-0221

    Last Modified: 16 Apr 2026

    The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.

    Published: 29 Apr 2003
    5
    Medium

    CVE-2003-1070

    Last Modified: 16 Apr 2026

    Unknown vulnerability in rpcbind for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (rpcbind crash).

    Published: 28 Apr 2003
    2.1
    Low

    CVE-2003-1072

    Last Modified: 16 Apr 2026

    Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).

    Published: 28 Apr 2003
    7.5
    High

    CVE-2003-0084

    Last Modified: 16 Apr 2026

    mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.

    Published: 28 Apr 2003
    7.2
    High

    CVE-2003-0188

    Last Modified: 16 Apr 2026

    lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.

    Published: 27 Apr 2003
    7.5
    High

    CVE-2003-0205

    Last Modified: 16 Apr 2026

    gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the ticker title of a URI.

    Published: 26 Apr 2003
    7.5
    High

    CVE-2003-0210

    Last Modified: 16 Apr 2026

    Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.

    Published: 26 Apr 2003
    7.5
    High

    CVE-2003-0213

    Last Modified: 16 Apr 2026

    ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.

    Published: 26 Apr 2003
    7.5
    High

    CVE-2003-0215

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.

    Published: 26 Apr 2003
    9.3
    Critical

    CVE-2003-0216

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.

    Published: 26 Apr 2003
    5
    Medium

    CVE-2003-0206

    Last Modified: 16 Apr 2026

    gkrellm-newsticker gkrellm plugin before 0.3-3.1 allows remote attackers to cause a denial of service (crash) via (1) link or (2) title elements that contain multiple lines.

    Published: 26 Apr 2003
    7.5
    High

    CVE-2003-0212

    Last Modified: 16 Apr 2026

    handleAccept in rinetd before 0.62 does not properly resize the connection list when it becomes full and sets an array index incorrectly, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of connections.

    Published: 26 Apr 2003
    4.6
    Medium

    CVE-2003-0214

    Last Modified: 16 Apr 2026

    run-mailcap in mime-support 3.22 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 26 Apr 2003
    5
    Medium

    CVE-2002-1562

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.

    Published: 26 Apr 2003
    7.5
    High

    CVE-2003-0113

    Last Modified: 16 Apr 2026

    Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.

    Published: 26 Apr 2003
    5
    Medium

    CVE-2003-0114

    Last Modified: 16 Apr 2026

    The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.

    Published: 26 Apr 2003
    5
    Medium

    CVE-2003-0116

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."

    Published: 26 Apr 2003
    4.6
    Medium

    CVE-2003-0112

    Last Modified: 16 Apr 2026

    Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.

    Published: 26 Apr 2003
    10
    Critical

    CVE-2002-1468

    Last Modified: 16 Apr 2026

    Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.

    Published: 22 Apr 2003
    7.5
    High

    CVE-2002-1469

    Last Modified: 16 Apr 2026

    scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

    Published: 22 Apr 2003
    7.5
    High

    CVE-2002-1477

    Last Modified: 16 Apr 2026

    graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.

    Published: 22 Apr 2003
    10
    Critical

    CVE-2002-1478

    Last Modified: 16 Apr 2026

    Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.

    Published: 22 Apr 2003
    5
    Medium

    CVE-2002-1471

    Last Modified: 16 Apr 2026

    The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.

    Published: 22 Apr 2003
    4.6
    Medium

    CVE-2002-1479

    Last Modified: 16 Apr 2026

    Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.

    Published: 22 Apr 2003
    4.6
    Medium

    CVE-2002-1476

    Last Modified: 16 Apr 2026

    Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the boundaries of the new_categories category array, as exploitable through programs such as xterm and zsh.

    Published: 22 Apr 2003
    5
    Medium

    CVE-2003-1054

    Last Modified: 16 Apr 2026

    mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.

    Published: 16 Apr 2003
    5
    Medium

    CVE-2003-0211

    Last Modified: 16 Apr 2026

    Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.

    Published: 16 Apr 2003
    10
    Critical

    CVE-2003-0209

    Last Modified: 16 Apr 2026

    Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.

    Published: 16 Apr 2003
    5
    Medium

    CVE-2003-0110

    Last Modified: 16 Apr 2026

    The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.

    Published: 15 Apr 2003
    5
    Medium

    CVE-2003-0163

    Last Modified: 16 Apr 2026

    decrypt_msg for the Gaim-Encryption GAIM plugin 1.15 and earlier does not properly validate a message length parameter, which allows remote attackers to cause a denial of service (crash) via a negative length, which overwrites arbitrary heap memory with a zero byte.

    Published: 15 Apr 2003
    6.4
    Medium

    CVE-2003-0198

    Last Modified: 16 Apr 2026

    Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.

    Published: 15 Apr 2003