CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2002-1556

    Last Modified: 16 Apr 2026

    Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR).

    Published: 18 Mar 2003
    4.6
    Medium

    CVE-2003-1095

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2003-0080

    Last Modified: 16 Apr 2026

    The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.

    Published: 17 Mar 2003
    7.2
    High

    CVE-2003-0127

    Last Modified: 16 Apr 2026

    The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.

    Published: 17 Mar 2003
    1.2
    Low

    CVE-2003-0086

    Last Modified: 16 Apr 2026

    The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.

    Published: 15 Mar 2003
    10
    Critical

    CVE-2003-0085

    Last Modified: 16 Apr 2026

    Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.

    Published: 15 Mar 2003
    5
    Medium

    CVE-2003-0137

    Last Modified: 16 Apr 2026

    SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings.

    Published: 14 Mar 2003
    7.2
    High

    CVE-2003-0144

    Last Modified: 16 Apr 2026

    Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.

    Published: 14 Mar 2003
    10
    Critical

    CVE-2003-0030

    Last Modified: 16 Apr 2026

    Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select.

    Published: 14 Mar 2003
    5
    Medium

    CVE-2003-0147

    Last Modified: 16 Apr 2026

    OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).

    Published: 14 Mar 2003
    7.5
    High

    CVE-2003-0121

    Last Modified: 16 Apr 2026

    Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version header field, which is processed by some mail clients.

    Published: 13 Mar 2003
    7.5
    High

    CVE-2003-0126

    Last Modified: 16 Apr 2026

    The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities.

    Published: 13 Mar 2003
    4.6
    Medium

    CVE-2003-0124

    Last Modified: 16 Apr 2026

    man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man.

    Published: 11 Mar 2003
    7.5
    High

    CVE-2003-0159

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 9 Mar 2003
    9
    Critical

    CVE-2003-0150

    Last Modified: 16 Apr 2026

    MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.

    Published: 8 Mar 2003
    7.5
    High

    CVE-2003-0081

    Last Modified: 16 Apr 2026

    Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.

    Published: 8 Mar 2003
    5
    Medium

    CVE-2003-0103

    Last Modified: 16 Apr 2026

    Format string vulnerability in Nokia 6210 handset allows remote attackers to cause a denial of service (crash, lockup, or restart) via a Multi-Part vCard with fields containing a large number of format string specifiers.

    Published: 7 Mar 2003
    1.2
    Low

    CVE-2003-0120

    Last Modified: 16 Apr 2026

    adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.

    Published: 7 Mar 2003
    6.8
    Medium

    CVE-2003-0009

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious script in the topic parameter.

    Published: 7 Mar 2003
    5
    Medium

    CVE-2003-0051

    Last Modified: 16 Apr 2026

    parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.

    Published: 7 Mar 2003
    5
    Medium

    CVE-2003-0052

    Last Modified: 16 Apr 2026

    parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.

    Published: 7 Mar 2003
    4.3
    Medium

    CVE-2003-0053

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.

    Published: 7 Mar 2003
    7.5
    High

    CVE-2003-0054

    Last Modified: 16 Apr 2026

    Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.

    Published: 7 Mar 2003
    10
    Critical

    CVE-2003-0033

    Last Modified: 16 Apr 2026

    Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.

    Published: 7 Mar 2003
    7.5
    High

    CVE-2003-0050

    Last Modified: 16 Apr 2026

    parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.

    Published: 7 Mar 2003
    7.5
    High

    CVE-2003-0055

    Last Modified: 16 Apr 2026

    Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.

    Published: 7 Mar 2003
    2.1
    Low

    CVE-2003-1077

    Last Modified: 16 Apr 2026

    Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).

    Published: 5 Mar 2003
    2.6
    Low

    CVE-2003-1581

    Last Modified: 11 Apr 2025

    The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

    Published: 4 Mar 2003
    4.6
    Medium

    CVE-2003-0102

    Last Modified: 16 Apr 2026

    Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).

    Published: 4 Mar 2003
    7.5
    High

    CVE-2003-0064

    Last Modified: 16 Apr 2026

    The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 3 Mar 2003
    10
    Critical

    CVE-2003-0095

    Last Modified: 16 Apr 2026

    Buffer overflow in ORACLE.EXE for Oracle Database Server 9i, 8i, 8.1.7, and 8.0.6 allows remote attackers to execute arbitrary code via a long username that is provided during login, as exploitable through client applications that perform their own authentication, as demonstrated using LOADPSP.

    Published: 3 Mar 2003
    7.5
    High

    CVE-2003-0024

    Last Modified: 16 Apr 2026

    The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.

    Published: 3 Mar 2003
    5
    Medium

    CVE-2003-0021

    Last Modified: 16 Apr 2026

    The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.

    Published: 3 Mar 2003
    7.5
    High

    CVE-2003-0068

    Last Modified: 16 Apr 2026

    The Eterm terminal emulator 0.9.1 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 3 Mar 2003
    7.2
    High

    CVE-2003-0087

    Last Modified: 16 Apr 2026

    Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm.

    Published: 3 Mar 2003
    7.2
    High

    CVE-2003-0088

    Last Modified: 16 Apr 2026

    TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.

    Published: 3 Mar 2003
    7.5
    High

    CVE-2003-0097

    Last Modified: 16 Apr 2026

    Unknown vulnerability in CGI module for PHP 4.3.0 allows attackers to access arbitrary files as the PHP user, and possibly execute PHP code, by bypassing the CGI force redirect settings (cgi.force_redirect or --enable-force-cgi-redirect).

    Published: 3 Mar 2003
    7.5
    High

    CVE-2003-0100

    Last Modified: 16 Apr 2026

    Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.

    Published: 3 Mar 2003
    7.5
    High

    CVE-2002-0842

    Last Modified: 16 Apr 2026

    Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" response, which causes the format string specifiers to be returned from dav_lookup_uri() in mod_dav.c, which is then used in a call to ap_log_rerror().

    Published: 3 Mar 2003
    7.5
    High

    CVE-2003-0065

    Last Modified: 16 Apr 2026

    The uxterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 3 Mar 2003
    5
    Medium

    CVE-2003-0094

    Last Modified: 16 Apr 2026

    A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed.

    Published: 3 Mar 2003
    10
    Critical

    CVE-2002-1337

    Last Modified: 16 Apr 2026

    Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

    Published: 3 Mar 2003
    7.5
    High

    CVE-2003-1078

    Last Modified: 16 Apr 2026

    The FTP client for Solaris 2.6, 7, and 8 with the debug (-d) flag enabled displays the user password on the screen during login.

    Published: 28 Feb 2003
    7.5
    High

    CVE-2003-0146

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in NetPBM 9.20 and earlier, and possibly other versions, may allow remote attackers to cause a denial of service or execute arbitrary code via "maths overflow errors" such as (1) integer signedness errors or (2) integer overflows, which lead to buffer overflows.

    Published: 28 Feb 2003
    5
    Medium

    CVE-2003-0108

    Last Modified: 16 Apr 2026

    isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.

    Published: 27 Feb 2003
    7.5
    High

    CVE-2003-0049

    Last Modified: 16 Apr 2026

    Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.

    Published: 26 Feb 2003
    10
    Critical

    CVE-2003-0098

    Last Modified: 16 Apr 2026

    Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.

    Published: 26 Feb 2003
    7.2
    High

    CVE-2003-0099

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.

    Published: 26 Feb 2003
    10
    Critical

    CVE-2003-0101

    Last Modified: 16 Apr 2026

    miniserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (CRLF) in Base-64 encoded strings during Basic authentication, which allows remote attackers to spoof a session ID and gain root privileges.

    Published: 26 Feb 2003
    7.8
    High

    CVE-2003-0855

    Last Modified: 16 Apr 2026

    Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.

    Published: 25 Feb 2003