4.3
    Medium

    CVE-2003-1519

    Last Modified: 9 Dec 2012

    Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web script or HTML via the query parameter to the search program.

    Source:ComSec
    Published:31 Dec 2003
    7.8
    High

    CVE-2003-1518

    Last Modified: 9 Dec 2012

    Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message.

    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1517

    Last Modified: 9 Dec 2012

    cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, which leaks the path in an error message.

    Source:Dr_Ponidi
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1516

    Last Modified: 9 Dec 2012

    The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet.

    Source:Marc Schoenefeld
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1513

    Last Modified: 9 Dec 2012

    Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) env.jsp, (2) form.jsp, (3) session.jsp, (4) the move parameter to tictactoe.jsp, or the (5) name or (6) comment fields to guestbook.jsp.

    Source:Donnie Werner
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1512

    Last Modified: 13 Oct 2017

    Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.

    Source:Takara Takaishi
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1511

    Last Modified: 9 Dec 2012

    Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet.

    Source:Oliver Karow
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1506

    Last Modified: 9 Dec 2012

    Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.

    Source:Richard Maudsley
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1505

    Last Modified: 9 Dec 2012

    Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.

    Source:Andreas Boeckler
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1504

    Last Modified: 9 Dec 2012

    SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) vadmin_login or (2) vadmin_pass cookie in a request to goldlink.php.

    Source:Weke
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1499

    Last Modified: 9 Dec 2012

    Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the infolder parameter.

    Source:Ezhilan
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1498

    Last Modified: 9 Dec 2012

    Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject arbitrary web script or HTML via the zoom_query parameter.

    Source:Ezhilan
    Published:31 Dec 2003
    6.4
    Medium

    CVE-2003-1488

    Last Modified: 7 Nov 2012

    The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.

    Source:frog
    Published:31 Dec 2003
    5.8
    Medium

    CVE-2003-1481

    Last Modified: 4 Oct 2017

    CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer.

    Source:Yaroslav Polyakov
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1480

    Last Modified: 8 Nov 2012

    MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.

    Source:Secret Squirrel
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1478

    Last Modified: 8 Nov 2012

    Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.

    Source:Joachim_Strombergson
    Published:31 Dec 2003
    4.6
    Medium

    CVE-2003-1473

    Last Modified: 9 Nov 2012

    Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable.

    Source:Knud Erik Hojgaard
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1472

    Last Modified: 8 Nov 2012

    Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long banner.

    Source:Over_G
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1469

    Last Modified: 7 Nov 2012

    The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.

    Source:Network Intelligence
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1468

    Last Modified: 10 Nov 2012

    The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.

    Source:Rynho Zeros Web
    Published:31 Dec 2003
    3.5
    Low

    CVE-2003-1463

    Last Modified: 7 Nov 2012

    Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter.

    Published:31 Dec 2003
    7.2
    High

    CVE-2003-1461

    Last Modified: 8 Nov 2012

    Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument. NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).

    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1459

    Last Modified: 27 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php.

    Source:Charles Reinold
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1456

    Last Modified: 7 Nov 2012

    Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via unknown attack vectors.

    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1453

    Last Modified: 7 Nov 2012

    Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.

    Source:magistrat
    Published:31 Dec 2003
    3.6
    Low

    CVE-2003-1452

    Last Modified: 25 Feb 2016

    Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.

    Source:Xpl017Elz
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1450

    Last Modified: 27 Oct 2012

    BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message.

    Source:argv
    Published:31 Dec 2003
    4.6
    Medium

    CVE-2003-1445

    Last Modified: 25 Oct 2012

    Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.

    Source:3APA3A
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1442

    Last Modified: 25 Oct 2012

    The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.

    Source:Davide Del Vecchio
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1436

    Last Modified: 24 Oct 2012

    PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.

    Source:Havenard
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1435

    Last Modified: 27 Oct 2012

    SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.

    Source:David Zentner
    Published:31 Dec 2003
    7.1
    High

    CVE-2003-1431

    Last Modified: 24 Oct 2012

    Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.

    Source:Auriemma Luigi
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1430

    Last Modified: 24 Oct 2012

    Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.

    Source:Auriemma Luigi
    Published:31 Dec 2003
    6.4
    Medium

    CVE-2003-1427

    Last Modified: 25 Oct 2012

    Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.

    Source:stickler
    Published:31 Dec 2003
    10
    Critical

    CVE-2003-1425

    Last Modified: 27 Oct 2012

    guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

    Source:bob
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1419

    Last Modified: 28 Oct 2012

    Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.

    Source:dwm
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1414

    Last Modified: 28 Oct 2012

    Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.

    Source:Joe Testa
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1412

    Last Modified: 28 Oct 2012

    PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5) 3departaments/index.php, and (6) 2groupd/index.php in 2administration/; or (7) the base parameter to include/help.php.

    Source:Karol Wiesek
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1411

    Last Modified: 25 Oct 2012

    PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.

    Source:MGhz
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1410

    Last Modified: 25 Oct 2012

    PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.

    Source:MGhz
    Published:31 Dec 2003
    5
    Medium

    CVE-2003-1409

    Last Modified: 24 Oct 2012

    TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.

    Source:Rynho Zeros Web
    Published:31 Dec 2003
    7.2
    High

    CVE-2003-1407

    Last Modified: 25 Oct 2012

    Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.

    Source:3APA3A
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1406

    Last Modified: 25 Oct 2012

    PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.

    Source:frog
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1405

    Last Modified: 25 Oct 2012

    DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.

    Source:frog
    Published:31 Dec 2003
    5.8
    Medium

    CVE-2003-1401

    Last Modified: 25 Oct 2012

    login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.

    Source:frog
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1400

    Last Modified: 24 Oct 2012

    Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.

    Source:delusion
    Published:31 Dec 2003
    4.3
    Medium

    CVE-2003-1397

    Last Modified: 25 Oct 2012

    The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.

    Source:Marc Schoenefeld
    Published:31 Dec 2003
    6.8
    Medium

    CVE-2003-1396

    Last Modified: 8 Nov 2012

    Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.

    Source:imagine & nesumin
    Published:31 Dec 2003
    7.5
    High

    CVE-2003-1387

    Last Modified: 28 Oct 2012

    Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.

    Source:nesumin
    Published:31 Dec 2003
    6.4
    Medium

    CVE-2003-1386

    Last Modified: 28 Oct 2012

    AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.

    Source:Martin Eiszner
    Published:31 Dec 2003