CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2003-0133

    Last Modified: 16 Apr 2026

    GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.

    Published: 2 Apr 2003
    7.5
    High

    CVE-2003-0168

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.

    Published: 1 Apr 2003
    5
    Medium

    CVE-2003-0169

    Last Modified: 16 Apr 2026

    hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.

    Published: 1 Apr 2003
    7.2
    High

    CVE-2003-0091

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.

    Published: 1 Apr 2003
    7.2
    High

    CVE-2003-0092

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.

    Published: 1 Apr 2003
    7.5
    High

    CVE-2003-0689

    Last Modified: 16 Apr 2026

    The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.

    Published: 1 Apr 2003
    7.5
    High

    CVE-2003-0135

    Last Modified: 16 Apr 2026

    vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.

    Published: 1 Apr 2003
    5
    Medium

    CVE-2002-1531

    Last Modified: 16 Apr 2026

    The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter.

    Published: 31 Mar 2003
    7.2
    High

    CVE-2002-1548

    Last Modified: 16 Apr 2026

    Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."

    Published: 31 Mar 2003
    4.3
    Medium

    CVE-2002-1529

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter.

    Published: 31 Mar 2003
    5
    Medium

    CVE-2002-1547

    Last Modified: 16 Apr 2026

    Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability than CVE-2001-0144.

    Published: 31 Mar 2003
    7.5
    High

    CVE-2002-1549

    Last Modified: 16 Apr 2026

    Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 31 Mar 2003
    5
    Medium

    CVE-2002-1534

    Last Modified: 16 Apr 2026

    Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share.

    Published: 31 Mar 2003
    10
    Critical

    CVE-2002-1537

    Last Modified: 16 Apr 2026

    admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".

    Published: 31 Mar 2003
    5
    Medium

    CVE-2002-1532

    Last Modified: 16 Apr 2026

    The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it.

    Published: 31 Mar 2003
    4.6
    Medium

    CVE-2002-1550

    Last Modified: 16 Apr 2026

    dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 31 Mar 2003
    7.5
    High

    CVE-2002-1552

    Last Modified: 16 Apr 2026

    Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager.

    Published: 31 Mar 2003
    10
    Critical

    CVE-2002-1560

    Last Modified: 16 Apr 2026

    index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.

    Published: 31 Mar 2003
    5
    Medium

    CVE-2002-1530

    Last Modified: 16 Apr 2026

    The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.

    Published: 31 Mar 2003
    5
    Medium

    CVE-2002-1538

    Last Modified: 16 Apr 2026

    Acuma Acusend 4, and possibly earlier versions, allows remote authenticated users to read the reports of other users by inferring the full URL, whose name is easily predictable.

    Published: 31 Mar 2003
    7.2
    High

    CVE-2002-1540

    Last Modified: 16 Apr 2026

    The client for Symantec Norton AntiVirus Corporate Edition 7.5.x before 7.5.1 Build 62 and 7.6.x before 7.6.1 Build 35a runs winhlp32 with raised privileges, which allows local users to gain privileges by using certain features of winhlp32.

    Published: 31 Mar 2003
    7.5
    High

    CVE-2002-1541

    Last Modified: 16 Apr 2026

    BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).

    Published: 31 Mar 2003
    4.6
    Medium

    CVE-2002-1543

    Last Modified: 16 Apr 2026

    Buffer overflow in trek on NetBSD 1.5 through 1.5.3 allows local users to gain privileges via long keyboard input.

    Published: 31 Mar 2003
    5.1
    Medium

    CVE-2003-0141

    Last Modified: 16 Apr 2026

    The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287, which are treated as a very large length.

    Published: 29 Mar 2003
    7.5
    High

    CVE-2003-0167

    Last Modified: 16 Apr 2026

    Multiple off-by-one buffer overflows in the IMAP capability for Mutt 1.3.28 and earlier, and Balsa 1.2.4 and earlier, allow a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a specially crafted mail folder, a different vulnerability than CVE-2003-0140.

    Published: 29 Mar 2003
    7.5
    High

    CVE-2003-0172

    Last Modified: 16 Apr 2026

    Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a crash and possibly execute arbitrary code via a long filename argument.

    Published: 29 Mar 2003
    10
    Critical

    CVE-2003-0178

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.

    Published: 29 Mar 2003
    7.5
    High

    CVE-2003-0179

    Last Modified: 16 Apr 2026

    Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.

    Published: 29 Mar 2003
    5
    Medium

    CVE-2003-0180

    Last Modified: 16 Apr 2026

    Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.

    Published: 29 Mar 2003
    5
    Medium

    CVE-2003-0181

    Last Modified: 16 Apr 2026

    Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.

    Published: 29 Mar 2003
    10
    Critical

    CVE-2003-0161

    Last Modified: 16 Apr 2026

    The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.

    Published: 29 Mar 2003
    7.2
    High

    CVE-2003-1074

    Last Modified: 16 Apr 2026

    Unknown vulnerability in newtask for Solaris 9 allows local users to gain root privileges.

    Published: 28 Mar 2003
    4.6
    Medium

    CVE-2003-0165

    Last Modified: 16 Apr 2026

    Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.

    Published: 28 Mar 2003
    7.5
    High

    CVE-2003-0166

    Last Modified: 16 Apr 2026

    Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via negative arguments to functions such as (1) socket_recv, (2) socket_recvfrom, and possibly other functions.

    Published: 27 Mar 2003
    7.5
    High

    CVE-2003-0106

    Last Modified: 16 Apr 2026

    The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.

    Published: 27 Mar 2003
    9.8
    Critical

    CVE-2004-0772

    Last Modified: 16 Apr 2026

    Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.

    Published: 27 Mar 2003
    7.5
    High

    CVE-2003-0152

    Last Modified: 16 Apr 2026

    Unknown vulnerability in bonsai Mozilla CVS query tool allows remote attackers to execute arbitrary commands as the www-data user.

    Published: 26 Mar 2003
    6.8
    Medium

    CVE-2003-0154

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1) the file, root, or rev parameters to cvslog.cgi, (2) the file or root parameters to cvsblame.cgi, (3) various parameters to cvsquery.cgi, (4) the person parameter to showcheckins.cgi, (5) the module parameter to cvsqueryform.cgi, and (6) possibly other attack vectors as identified by Mozilla bug #146244.

    Published: 26 Mar 2003
    5
    Medium

    CVE-2002-1561

    Last Modified: 16 Apr 2026

    The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.

    Published: 26 Mar 2003
    5
    Medium

    CVE-2003-0153

    Last Modified: 16 Apr 2026

    bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.

    Published: 26 Mar 2003
    5
    Medium

    CVE-2003-0155

    Last Modified: 16 Apr 2026

    bonsai Mozilla CVS query tool allows remote attackers to gain access to the parameters page without authentication.

    Published: 26 Mar 2003
    7.5
    High

    CVE-2003-0162

    Last Modified: 16 Apr 2026

    Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.

    Published: 26 Mar 2003
    4.6
    Medium

    CVE-2002-0030

    Last Modified: 16 Apr 2026

    The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.

    Published: 26 Mar 2003
    7.5
    High

    CVE-2003-0010

    Last Modified: 16 Apr 2026

    Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.

    Published: 21 Mar 2003
    5
    Medium

    CVE-2003-0156

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Cross-Referencing Linux (LXR) allows remote attackers to read arbitrary files via .. (dot dot) sequences in the v parameter.

    Published: 21 Mar 2003
    Unknown

    CVE-2003-0157

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0138. Reason: This candidate is a reservation duplicate of CVE-2003-0138 due to incomplete coordination. Notes: All CVE users should reference CVE-2003-0138 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Mar 2003
    Unknown

    CVE-2003-0158

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2003-0139. Reason: This candidate is a reservation duplicate of CVE-2003-0139 due to incomplete coordination. Notes: All CVE users should reference CVE-2003-0139 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Mar 2003
    7.5
    High

    CVE-2003-0151

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.

    Published: 21 Mar 2003
    5
    Medium

    CVE-2003-0011

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.

    Published: 21 Mar 2003
    5
    Medium

    CVE-2003-1201

    Last Modified: 16 Apr 2026

    ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer, which allows remote attackers to cause a denial of service (segmentation fault).

    Published: 20 Mar 2003