CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2003-0111

    Last Modified: 16 Apr 2026

    The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."

    Published: 15 Apr 2003
    7.2
    High

    CVE-2003-0171

    Last Modified: 16 Apr 2026

    DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.

    Published: 15 Apr 2003
    7.2
    High

    CVE-2003-0173

    Last Modified: 16 Apr 2026

    xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges.

    Published: 15 Apr 2003
    2.1
    Low

    CVE-2003-0207

    Last Modified: 16 Apr 2026

    ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.

    Published: 15 Apr 2003
    4.3
    Medium

    CVE-2003-0208

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Macromedia Flash ad user tracking capability allows remote attackers to insert arbitrary Javascript via the clickTAG field.

    Published: 15 Apr 2003
    7.5
    High

    CVE-2002-1419

    Last Modified: 16 Apr 2026

    The upgrade of IRIX on Origin 3000 to 6.5.13 through 6.5.16 changes the MAC address of the system, which could modify intended access restrictions that are based on a MAC address.

    Published: 11 Apr 2003
    5
    Medium

    CVE-2002-1430

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters.

    Published: 11 Apr 2003
    7.5
    High

    CVE-2002-1412

    Last Modified: 16 Apr 2026

    Gallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified GALLERY_BASEDIR variable that points to a directory or URL that contains a Trojan horse init.php script.

    Published: 11 Apr 2003
    5
    Medium

    CVE-2002-1417

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot), which is mapped to the directory separator.

    Published: 11 Apr 2003
    7.2
    High

    CVE-2002-1420

    Last Modified: 16 Apr 2026

    Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check as a signed integer, but is later used as an unsigned integer during a data copying operation.

    Published: 11 Apr 2003
    7.5
    High

    CVE-2002-1435

    Last Modified: 16 Apr 2026

    class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url_fopen' setting is enabled via a URL in the config_atkroot parameter that points to the code.

    Published: 11 Apr 2003
    7.5
    High

    CVE-2002-1436

    Last Modified: 16 Apr 2026

    The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.

    Published: 11 Apr 2003
    5
    Medium

    CVE-2002-1443

    Last Modified: 16 Apr 2026

    The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.

    Published: 11 Apr 2003
    7.5
    High

    CVE-2002-1407

    Last Modified: 16 Apr 2026

    TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.

    Published: 11 Apr 2003
    7.5
    High

    CVE-2002-1413

    Last Modified: 16 Apr 2026

    RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.

    Published: 11 Apr 2003
    4.6
    Medium

    CVE-2002-1414

    Last Modified: 16 Apr 2026

    Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable.

    Published: 11 Apr 2003
    5
    Medium

    CVE-2002-1424

    Last Modified: 16 Apr 2026

    Buffer overflow in munpack in mpack 1.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 11 Apr 2003
    6.4
    Medium

    CVE-2002-1425

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.

    Published: 11 Apr 2003
    5
    Medium

    CVE-2002-1418

    Last Modified: 16 Apr 2026

    Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (ABEND) via a long module name.

    Published: 11 Apr 2003
    5
    Medium

    CVE-2002-1437

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences.

    Published: 11 Apr 2003
    5
    Medium

    CVE-2002-1438

    Last Modified: 16 Apr 2026

    The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.

    Published: 11 Apr 2003
    2.1
    Low

    CVE-2003-0136

    Last Modified: 16 Apr 2026

    psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.

    Published: 9 Apr 2003
    7.2
    High

    CVE-2003-0197

    Last Modified: 16 Apr 2026

    Buffer overflow gds_lock_mgr of Interbase Database 6.x allows local users to gain privileges via a long ISC_LOCK_ENV environment variable (INTERBASE_LOCK).

    Published: 8 Apr 2003
    7.5
    High

    CVE-2003-0203

    Last Modified: 16 Apr 2026

    Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.

    Published: 8 Apr 2003
    10
    Critical

    CVE-2003-0196

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.

    Published: 7 Apr 2003
    10
    Critical

    CVE-2003-0201

    Last Modified: 16 Apr 2026

    Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.

    Published: 7 Apr 2003
    5
    Medium

    CVE-2003-0244

    Last Modified: 16 Apr 2026

    The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.

    Published: 5 Apr 2003
    5
    Medium

    CVE-2002-1143

    Last Modified: 16 Apr 2026

    Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."

    Published: 3 Apr 2003
    5
    Medium

    CVE-2003-0134

    Last Modified: 16 Apr 2026

    Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names.

    Published: 3 Apr 2003
    7.5
    High

    CVE-2003-0204

    Last Modified: 16 Apr 2026

    KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.

    Published: 3 Apr 2003
    4.6
    Medium

    CVE-2002-1513

    Last Modified: 16 Apr 2026

    The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges.

    Published: 2 Apr 2003
    7.5
    High

    CVE-2002-1496

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header.

    Published: 2 Apr 2003
    7.2
    High

    CVE-2002-1514

    Last Modified: 16 Apr 2026

    gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.

    Published: 2 Apr 2003
    10
    Critical

    CVE-2002-1520

    Last Modified: 16 Apr 2026

    The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows remote attackers to access CLI with administrator privileges.

    Published: 2 Apr 2003
    2.1
    Low

    CVE-2002-1521

    Last Modified: 16 Apr 2026

    Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges.

    Published: 2 Apr 2003
    4.3
    Medium

    CVE-2002-1493

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag.

    Published: 2 Apr 2003
    2.1
    Low

    CVE-2002-1490

    Last Modified: 16 Apr 2026

    NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the TIOCSCTTY ioctl, which causes an integer overflow in a structure counter and sets the counter to zero, which frees memory that is still in use by other processes.

    Published: 2 Apr 2003
    5
    Medium

    CVE-2002-1491

    Last Modified: 16 Apr 2026

    The Cisco VPN 5000 Client for MacOS before 5.2.2 records the most recently used login password in plaintext when saving "Default Connection" settings, which could allow local users to gain privileges.

    Published: 2 Apr 2003
    5
    Medium

    CVE-2002-1501

    Last Modified: 16 Apr 2026

    The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078.

    Published: 2 Apr 2003
    2.1
    Low

    CVE-2002-1502

    Last Modified: 16 Apr 2026

    Symbolic link vulnerability in xbreaky before 0.5.5 allows local users to overwrite arbitrary files via a symlink from the user's .breakyhighscores file to the target file.

    Published: 2 Apr 2003
    4.3
    Medium

    CVE-2002-1497

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response.

    Published: 2 Apr 2003
    7.5
    High

    CVE-2002-1505

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.

    Published: 2 Apr 2003
    4.6
    Medium

    CVE-2002-1516

    Last Modified: 16 Apr 2026

    rpcbind in SGI IRIX, when using the -w command line switch, allows local users to overwrite arbitrary files via a symlink attack.

    Published: 2 Apr 2003
    4.6
    Medium

    CVE-2002-1517

    Last Modified: 16 Apr 2026

    fsr_efs in IRIX 6.5 allows local users to conduct unauthorized file activities via a symlink attack, possibly via the .fsrlast file.

    Published: 2 Apr 2003
    3.6
    Low

    CVE-2002-1518

    Last Modified: 16 Apr 2026

    mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local users to modify files and directories.

    Published: 2 Apr 2003
    10
    Critical

    CVE-2002-1519

    Last Modified: 16 Apr 2026

    Format string vulnerability in the CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in the password parameter.

    Published: 2 Apr 2003
    7.5
    High

    CVE-2002-1524

    Last Modified: 16 Apr 2026

    Buffer overflow in XML parser in wsabi.dll of Winamp 3 (1.0.0.488) allows remote attackers to execute arbitrary code via a skin file (.wal) with a long include file tag.

    Published: 2 Apr 2003
    5
    Medium

    CVE-2002-1528

    Last Modified: 16 Apr 2026

    MsmMask.exe in MondoSearch 4.4 allows remote attackers to obtain the source code of scripts via the mask parameter.

    Published: 2 Apr 2003
    4.3
    Medium

    CVE-2002-1494

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.

    Published: 2 Apr 2003
    5
    Medium

    CVE-2003-0132

    Last Modified: 16 Apr 2026

    A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.

    Published: 2 Apr 2003