CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2003-0145

    Last Modified: 16 Apr 2026

    Unknown vulnerability in tcpdump before 3.7.2 related to an inability to "Handle unknown RADIUS attributes properly," allows remote attackers to cause a denial of service (infinite loop), a different vulnerability than CAN-2003-0093.

    Published: 25 Feb 2003
    4.3
    Medium

    CVE-2003-1418

    Last Modified: 16 Apr 2026

    Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).

    Published: 25 Feb 2003
    7.3
    High

    CVE-2003-0063

    Last Modified: 16 Apr 2026

    The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 24 Feb 2003
    7.5
    High

    CVE-2003-0077

    Last Modified: 16 Apr 2026

    The hanterm (hanterm-xf) terminal emulator 2.0.5 and earlier, and possibly later versions, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 24 Feb 2003
    2.1
    Low

    CVE-2003-0079

    Last Modified: 16 Apr 2026

    The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.

    Published: 24 Feb 2003
    5
    Medium

    CVE-2003-0020

    Last Modified: 16 Apr 2026

    Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.

    Published: 24 Feb 2003
    7.5
    High

    CVE-2003-0066

    Last Modified: 16 Apr 2026

    The rxvt terminal emulator 2.7.8 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 24 Feb 2003
    6.8
    Medium

    CVE-2003-0070

    Last Modified: 16 Apr 2026

    VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 24 Feb 2003
    2.1
    Low

    CVE-2003-0071

    Last Modified: 16 Apr 2026

    The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.

    Published: 24 Feb 2003
    5
    Medium

    CVE-2003-0022

    Last Modified: 16 Apr 2026

    The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence.

    Published: 24 Feb 2003
    5
    Medium

    CVE-2003-0023

    Last Modified: 16 Apr 2026

    The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu.

    Published: 24 Feb 2003
    5
    Medium

    CVE-2003-0083

    Last Modified: 16 Apr 2026

    Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.

    Published: 24 Feb 2003
    7.5
    High

    CVE-2003-0107

    Last Modified: 16 Apr 2026

    Buffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using vsnprintf, allows attackers to cause a denial of service or possibly execute arbitrary code.

    Published: 22 Feb 2003
    Unknown

    CVE-2002-0841

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0842. Reason: This candidate is a duplicate of CVE-2002-0842. The duplicate assignment was made before public disclosure. Notes: none

    Published: 21 Feb 2003
    9
    Critical

    CVE-2003-0096

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Oracle 9i Database release 2, Release 1, 8i, 8.1.7, and 8.0.6 allow remote attackers to execute arbitrary code via (1) a long conversion string argument to the TO_TIMESTAMP_TZ function, (2) a long time zone argument to the TZ_OFFSET function, or (3) a long DIRECTORY parameter to the BFILENAME function.

    Published: 21 Feb 2003
    7.5
    High

    CVE-2003-0040

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.

    Published: 19 Feb 2003
    7.2
    High

    CVE-2003-0004

    Last Modified: 16 Apr 2026

    Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.

    Published: 19 Feb 2003
    7.5
    High

    CVE-2003-1326

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."

    Published: 19 Feb 2003
    7.2
    High

    CVE-2003-0062

    Last Modified: 16 Apr 2026

    Buffer overflow in Eset Software NOD32 for UNIX before 1.013 allows local users to execute arbitrary code via a long path name.

    Published: 19 Feb 2003
    7.5
    High

    CVE-2003-0075

    Last Modified: 16 Apr 2026

    Integer signedness error in the myFseek function of samplein.c for Blade encoder (BladeEnc) 0.94.2 and earlier allows remote attackers to execute arbitrary code via a negative offset value following a "fmt" wave chunk.

    Published: 19 Feb 2003
    7.5
    High

    CVE-2003-1328

    Last Modified: 16 Apr 2026

    The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."

    Published: 19 Feb 2003
    5
    Medium

    CVE-2003-0078

    Last Modified: 16 Apr 2026

    ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."

    Published: 19 Feb 2003
    5
    Medium

    CVE-2003-1079

    Last Modified: 16 Apr 2026

    Unknown vulnerability in UDP RPC for Solaris 2.5.1 through 9 for SPARC, and 2.5.1 through 8 for x86, allows remote attackers to cause a denial of service (memory consumption) via certain arguments in RPC calls that cause large amounts of memory to be allocated.

    Published: 18 Feb 2003
    5
    Medium

    CVE-2002-0669

    Last Modified: 16 Apr 2026

    The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause a denial of service by modifying the SIP_AUTHENTICATE_SCHEME value to force authentication of incoming calls, which does not notify the user when an authentication failure occurs.

    Published: 11 Feb 2003
    6.4
    Medium

    CVE-2003-0076

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the directory parser for Direct Connect 4 Linux (dcgui) before 0.2.2 allows remote attackers to read files outside the sharelist.

    Published: 11 Feb 2003
    1.2
    Low

    CVE-2003-1080

    Last Modified: 16 Apr 2026

    Unknown vulnerability in mail for Solaris 2.6 through 9 allows local users to read the email of other users.

    Published: 11 Feb 2003
    5.8
    Medium

    CVE-2003-0160

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.

    Published: 11 Feb 2003
    7.5
    High

    CVE-2003-0773

    Last Modified: 16 Apr 2026

    saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf.

    Published: 10 Feb 2003
    7.5
    High

    CVE-2003-0774

    Last Modified: 16 Apr 2026

    saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed.

    Published: 10 Feb 2003
    5
    Medium

    CVE-2003-0777

    Last Modified: 16 Apr 2026

    saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault).

    Published: 10 Feb 2003
    5
    Medium

    CVE-2003-0775

    Last Modified: 16 Apr 2026

    saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash).

    Published: 10 Feb 2003
    7.5
    High

    CVE-2003-0776

    Last Modified: 16 Apr 2026

    saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences.

    Published: 10 Feb 2003
    5
    Medium

    CVE-2003-0778

    Last Modified: 16 Apr 2026

    saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption).

    Published: 10 Feb 2003
    7.5
    High

    CVE-2003-0016

    Last Modified: 16 Apr 2026

    Apache before 2.0.44, when running on unpatched Windows 9x and Me operating systems, allows remote attackers to cause a denial of service or execute arbitrary code via an HTTP request containing MS-DOS device names.

    Published: 7 Feb 2003
    6.8
    Medium

    CVE-2003-0002

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.

    Published: 7 Feb 2003
    7.5
    High

    CVE-2003-0003

    Last Modified: 16 Apr 2026

    Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.

    Published: 7 Feb 2003
    5
    Medium

    CVE-2003-0007

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."

    Published: 7 Feb 2003
    5
    Medium

    CVE-2003-0017

    Last Modified: 16 Apr 2026

    Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.

    Published: 7 Feb 2003
    5
    Medium

    CVE-2003-0043

    Last Modified: 16 Apr 2026

    Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.

    Published: 7 Feb 2003
    5
    Medium

    CVE-2003-0027

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.

    Published: 7 Feb 2003
    5
    Medium

    CVE-2003-0045

    Last Modified: 16 Apr 2026

    Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.

    Published: 7 Feb 2003
    5
    Medium

    CVE-2002-1252

    Last Modified: 16 Apr 2026

    The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fields in an HTTP POST request that is processed by the SimpleFileHandler handler.

    Published: 7 Feb 2003
    7.2
    High

    CVE-2003-0019

    Last Modified: 16 Apr 2026

    uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.

    Published: 7 Feb 2003
    10
    Critical

    CVE-2003-1090

    Last Modified: 16 Apr 2026

    Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.

    Published: 6 Feb 2003
    Unknown

    CVE-2002-1404

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1348. Reason: This candidate is a reservation duplicate of CVE-2002-1348. Notes: All CVE users should reference CVE-2002-1348 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Feb 2003
    7.2
    High

    CVE-2003-0074

    Last Modified: 16 Apr 2026

    Format string vulnerability in mpmain.c for plpnfsd of the plptools package allows remote attackers to execute arbitrary code via the functions (1) debuglog, (2) errorlog, and (3) infolog.

    Published: 5 Feb 2003
    3.6
    Low

    CVE-2003-0018

    Last Modified: 16 Apr 2026

    Linux kernel 2.4.10 through 2.4.21-pre4 does not properly handle the O_DIRECT feature, which allows local attackers with write privileges to read portions of previously deleted files, or cause file system corruption.

    Published: 4 Feb 2003
    5
    Medium

    CVE-2003-1302

    Last Modified: 16 Apr 2026

    The IMAP functionality in PHP before 4.3.1 allows remote attackers to cause a denial of service via an e-mail message with a (1) To or (2) From header with an address that contains a large number of "\" (backslash) characters.

    Published: 4 Feb 2003
    7.2
    High

    CVE-2002-1160

    Last Modified: 16 Apr 2026

    The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.

    Published: 3 Feb 2003
    6.5
    Medium

    CVE-2003-1564

    Last Modified: 16 Apr 2026

    libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."

    Published: 2 Feb 2003