CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2003-0048

    Last Modified: 16 Apr 2026

    PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

    Published: 1 Feb 2003
    7.2
    High

    CVE-2003-0056

    Last Modified: 16 Apr 2026

    Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command line argument.

    Published: 1 Feb 2003
    4.6
    Medium

    CVE-2003-0047

    Last Modified: 16 Apr 2026

    SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

    Published: 1 Feb 2003
    7.5
    High

    CVE-2003-0057

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Hypermail 2 before 2.1.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code (1) via a long attachment filename that is not properly handled by the hypermail executable, or (2) by connecting to the mail CGI program from an IP address that reverse-resolves to a long hostname.

    Published: 1 Feb 2003
    7.5
    High

    CVE-2003-0060

    Last Modified: 16 Apr 2026

    Format string vulnerabilities in the logging routines for MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in Kerberos principal names.

    Published: 1 Feb 2003
    4.6
    Medium

    CVE-2003-0046

    Last Modified: 16 Apr 2026

    AbsoluteTelnet SSH2 client does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.

    Published: 1 Feb 2003
    10
    Critical

    CVE-2003-0041

    Last Modified: 16 Apr 2026

    Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.

    Published: 31 Jan 2003
    4.3
    Medium

    CVE-2003-0038

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via the (1) email or (2) language parameters.

    Published: 29 Jan 2003
    7.5
    High

    CVE-2003-0037

    Last Modified: 16 Apr 2026

    Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.

    Published: 29 Jan 2003
    6.8
    Medium

    CVE-2003-0044

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.

    Published: 29 Jan 2003
    5
    Medium

    CVE-2003-0042

    Last Modified: 16 Apr 2026

    Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.

    Published: 29 Jan 2003
    5
    Medium

    CVE-2002-0036

    Last Modified: 16 Apr 2026

    Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value.

    Published: 29 Jan 2003
    7.8
    High

    CVE-2003-1329

    Last Modified: 16 Apr 2026

    ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.

    Published: 29 Jan 2003
    5
    Medium

    CVE-2003-0058

    Last Modified: 16 Apr 2026

    MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.

    Published: 28 Jan 2003
    7.5
    High

    CVE-2003-0059

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the chk_trans.c of the libkrb5 library for MIT Kerberos V5 before 1.2.5 allows users from one realm to impersonate users in other realms that have the same inter-realm keys.

    Published: 28 Jan 2003
    5
    Medium

    CVE-2003-1075

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the FTP server (in.ftpd) for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (temporary FTP server hang), which affects other active mode FTP clients.

    Published: 27 Jan 2003
    5
    Medium

    CVE-2003-0073

    Last Modified: 16 Apr 2026

    Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.

    Published: 23 Jan 2003
    7.2
    High

    CVE-2003-0035

    Last Modified: 16 Apr 2026

    Buffer overflow in escputil, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long printer-name command line argument.

    Published: 22 Jan 2003
    6.2
    Medium

    CVE-2003-0036

    Last Modified: 16 Apr 2026

    ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".

    Published: 22 Jan 2003
    7.2
    High

    CVE-2003-0034

    Last Modified: 16 Apr 2026

    Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.

    Published: 22 Jan 2003
    7.5
    High

    CVE-2003-0015

    Last Modified: 16 Apr 2026

    Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.

    Published: 20 Jan 2003
    7.2
    High

    CVE-2002-1403

    Last Modified: 16 Apr 2026

    dhcpcd DHCP client daemon 1.3.22 and earlier allows local users to execute arbitrary code via shell metacharacters that are fed from a dhcpd .info script into a .exe script.

    Published: 17 Jan 2003
    7.5
    High

    CVE-2003-0013

    Last Modified: 16 Apr 2026

    The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.

    Published: 17 Jan 2003
    5
    Medium

    CVE-2002-1390

    Last Modified: 16 Apr 2026

    The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbitrary files via a crafted URL.

    Published: 17 Jan 2003
    2.1
    Low

    CVE-2003-0012

    Last Modified: 16 Apr 2026

    The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.

    Published: 17 Jan 2003
    5
    Medium

    CVE-2003-0032

    Last Modified: 16 Apr 2026

    Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.

    Published: 17 Jan 2003
    7.5
    High

    CVE-2003-0025

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database activities and possibly gain privileges via certain database functions such as check_prefs() in db.pgsql, as demonstrated using mailbox.php3.

    Published: 15 Jan 2003
    7.5
    High

    CVE-2003-0031

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).

    Published: 15 Jan 2003
    5
    Medium

    CVE-2003-0039

    Last Modified: 16 Apr 2026

    ISC dhcrelay (dhcp-relay) 3.0rc9 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (packet storm) via a certain BOOTP packet that is forwarded to a broadcast MAC address, causing an infinite loop that is not restricted by a hop count.

    Published: 15 Jan 2003
    7.5
    High

    CVE-2003-0026

    Last Modified: 16 Apr 2026

    Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long hostname.

    Published: 15 Jan 2003
    4.6
    Medium

    CVE-2003-0014

    Last Modified: 16 Apr 2026

    gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 11 Jan 2003
    5
    Medium

    CVE-2003-0093

    Last Modified: 16 Apr 2026

    The RADIUS decoder in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service (crash) via an invalid RADIUS packet with a header length field of 0, which causes tcpdump to generate data within an infinite loop.

    Published: 10 Jan 2003
    10
    Critical

    CVE-2002-1399

    Last Modified: 16 Apr 2026

    Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2).

    Published: 8 Jan 2003
    7.5
    High

    CVE-2002-0627

    Last Modified: 16 Apr 2026

    The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requests.

    Published: 7 Jan 2003
    5
    Medium

    CVE-2002-0630

    Last Modified: 16 Apr 2026

    The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via long or malformed ICMP packets.

    Published: 7 Jan 2003
    5
    Medium

    CVE-2003-0001

    Last Modified: 16 Apr 2026

    Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

    Published: 6 Jan 2003
    10
    Critical

    CVE-2002-0626

    Last Modified: 16 Apr 2026

    Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized activities.

    Published: 3 Jan 2003
    7.5
    High

    CVE-2002-0628

    Last Modified: 16 Apr 2026

    The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.

    Published: 3 Jan 2003
    5
    Medium

    CVE-2002-0629

    Last Modified: 16 Apr 2026

    The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via multiple connections to the server.

    Published: 3 Jan 2003
    Unknown

    CVE-2002-1263

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1295. Reason: This candidate is a reservation duplicate of CVE-2002-1295. Notes: All CVE users should reference CVE-2002-1295 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Jan 2003
    2.1
    Low

    CVE-2003-1071

    Last Modified: 16 Apr 2026

    rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to come from arbitrary user IDs by closing stderr before executing wall, then supplying a spoofed from header.

    Published: 3 Jan 2003
    4.3
    Medium

    CVE-2002-1388

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MHonArc before 2.5.14 allows remote attackers to inject arbitrary HTML into web archive pages via HTML mail messages.

    Published: 2 Jan 2003
    4.6
    Medium

    CVE-2002-1389

    Last Modified: 16 Apr 2026

    Buffer overflow in typespeed 0.4.2 and earlier allows local users to gain privileges via long input.

    Published: 2 Jan 2003
    7.8
    High

    CVE-2002-2419

    Last Modified: 16 Apr 2026

    Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2418

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP) 1.33 beta 7 allows remote attackers to inject arbitrary web script or HTML via the URL, which is inserted into an error page.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2417

    Last Modified: 16 Apr 2026

    acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2414

    Last Modified: 16 Apr 2026

    Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash).

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2410

    Last Modified: 16 Apr 2026

    openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.

    Published: 31 Dec 2002
    3.5
    Low

    CVE-2002-2409

    Last Modified: 16 Apr 2026

    Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose name is a hex-encoded user ID.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2400

    Last Modified: 16 Apr 2026

    Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP POST request.

    Published: 31 Dec 2002