5
    Medium

    CVE-2003-0864

    Last Modified: 9 Dec 2012

    Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.

    Source:millhouse
    Published:15 Oct 2003
    7.5
    High

    CVE-2003-0863

    Last Modified: 25 Nov 2012

    The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.

    Source:Michal Krause
    Published:15 Oct 2003
    2.1
    Low

    CVE-2003-0854

    Last Modified: 6 Mar 2019

    ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.

    Source:Angelo Rosiello
    Published:15 Oct 2003
    5
    Medium

    CVE-2003-0853

    Last Modified: 9 Dec 2012

    An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.

    Source:druid
    Published:15 Oct 2003
    7.5
    High

    CVE-2003-0849

    Last Modified: 27 Oct 2016

    Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.

    Source:kokanin
    Published:9 Oct 2003
    4.6
    Medium

    CVE-2003-0848

    Last Modified: 9 Dec 2012

    Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.

    Source:Patrik Hornik
    Published:6 Oct 2003
    4.6
    Medium

    CVE-2003-0847

    Last Modified: 8 Dec 2012

    SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.

    Source:Nash Leon
    Published:9 Oct 2003
    7.5
    High

    CVE-2003-0845

    Last Modified: 8 Dec 2012

    Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.

    Source:Marc Schoenefeld
    Published:5 Oct 2003
    7.5
    High

    CVE-2003-0842

    Last Modified: 22 Nov 2017

    Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header.

    Source:xCrZx
    Published:9 Oct 2003
    7.2
    High

    CVE-2003-0840

    Last Modified: 9 Dec 2012

    Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

    Source:Davide Del Vecchio
    Published:9 Oct 2003
    7.5
    High

    CVE-2003-0838

    Last Modified: 3 Dec 2012

    Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).

    Source:http-equiv
    Published:7 Oct 2003
    7.5
    High

    CVE-2003-0835

    Last Modified: 24 Nov 2016

    Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.

    Source:Otero Hernan
    Published:1 Oct 2003
    7.2
    High

    CVE-2003-0834

    Last Modified: 14 Nov 2016

    Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.

    Source:Marco Ivaldi
    Published:6 Nov 2003
    7.5
    High

    CVE-2003-0833

    Last Modified: 6 Dec 2012

    Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname.

    Source:jsk
    Published:1 Oct 2003
    9
    Critical

    CVE-2003-0831

    Last Modified: 5 Dec 2012

    ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a buffer overflow using certain files.

    Source:netris
    Published:25 Sept 2003
    4.6
    Medium

    CVE-2003-0830

    Last Modified: 6 Dec 2012

    Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.

    Source:demz
    Published:1 Oct 2003
    7.5
    High

    CVE-2003-0826

    Last Modified: 5 Dec 2012

    lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long input is provided, which could allow remote attackers to execute arbitrary code via a heap-based buffer overflow attack.

    Source:Carl Livitt
    Published:23 Sept 2003
    7.5
    High

    CVE-2003-0822

    Last Modified: 16 Apr 2026

    Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.

    Source:Adik
    Published:18 Nov 2003
    7.5
    High

    CVE-2003-0818

    Last Modified: 16 Apr 2026

    Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.

    Source:Christophe Devine
    Published:11 Feb 2004
    7.5
    High

    CVE-2003-0816

    Last Modified: 31 Dec 2012

    Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.

    Source:Liu Die Yu
    Published:14 Jan 2004
    7.5
    High

    CVE-2003-0812

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.

    Source:snooq
    Published:18 Nov 2003
    7.5
    High

    CVE-2003-0809

    Last Modified: 3 Dec 2012

    Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.

    Source:http-equiv
    Published:8 Oct 2003
    7.5
    High

    CVE-2003-0805

    Last Modified: 25 Feb 2016

    Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.

    Source:V9
    Published:19 Sept 2003
    7.5
    High

    CVE-2003-0803

    Last Modified: 4 Dec 2012

    Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.

    Source:@stake
    Published:18 Sept 2003
    5
    Medium

    CVE-2003-0802

    Last Modified: 4 Dec 2012

    Nokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).

    Source:@stake
    Published:18 Sept 2003
    4.3
    Medium

    CVE-2003-0801

    Last Modified: 4 Dec 2012

    Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.

    Source:Ollie Whitehouse
    Published:18 Sept 2003
    5
    Medium

    CVE-2003-0795

    Last Modified: 13 Dec 2012

    The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.

    Source:Jonny Robertson
    Published:15 Oct 2003
    7.2
    High

    CVE-2003-0783

    Last Modified: 25 Feb 2016

    Multiple buffer overflows in hztty 2.0 allow local users to gain root privileges.

    Source:c0wboy
    Published:23 Sept 2003
    9
    Critical

    CVE-2003-0780

    Last Modified: 4 Dec 2012

    Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field.

    Source:Frank DENIS
    Published:10 Sept 2003
    7.5
    High

    CVE-2003-0772

    Last Modified: 2 Dec 2012

    Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.

    Source:xfocus
    Published:12 Sept 2003
    7.5
    High

    CVE-2003-0770

    Last Modified: 5 Nov 2012

    FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters, which allows remote attackers to execute arbitrary code when the cookie is inserted into a Perl "eval" statement.

    Source:Nick Cleaton
    Published:12 Sept 2003
    4.3
    Medium

    CVE-2003-0769

    Last Modified: 3 Dec 2012

    Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.

    Source:Donnie Werner
    Published:12 Sept 2003
    7.5
    High

    CVE-2003-0767

    Last Modified: 16 Apr 2026

    Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers to cause a denial of service and execute arbitrary code via a client request with a large length value.

    Source:Luigi Auriemma
    Published:12 Sept 2003
    7.5
    High

    CVE-2003-0766

    Last Modified: 3 Dec 2012

    Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary code via (1) a long FTP banner, (2) a long response to a USER command, or (3) a long response to a PASS command.

    Source:Bahaa Naamneh
    Published:12 Sept 2003
    7.5
    High

    CVE-2003-0765

    Last Modified: 3 Dec 2012

    The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.

    Source:Luigi Auriemma
    Published:12 Sept 2003
    4.3
    Medium

    CVE-2003-0763

    Last Modified: 3 Dec 2012

    Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the method parameter, as demonstrated using the PAGE parameter.

    Source:Bahaa Naamneh
    Published:12 Sept 2003
    7.5
    High

    CVE-2003-0762

    Last Modified: 2 Dec 2012

    Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).

    Source:pokleyzz
    Published:12 Sept 2003
    5
    Medium

    CVE-2003-0760

    Last Modified: 2 Dec 2012

    Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.

    Source:Luca Ercoli
    Published:12 Sept 2003
    7.2
    High

    CVE-2003-0759

    Last Modified: 22 Nov 2017

    Buffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long command line argument.

    Source:Juan Escriba
    Published:19 Sept 2003
    7.2
    High

    CVE-2003-0758

    Last Modified: 3 Dec 2012

    Buffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long command line argument.

    Source:Martinez Kuhn
    Published:19 Sept 2003
    5
    Medium

    CVE-2003-0757

    Last Modified: 2 Dec 2012

    Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.

    Source:Jim Becher
    Published:6 Sept 2003
    10
    Critical

    CVE-2003-0755

    Last Modified: 5 Dec 2016

    Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory names and listing them with a LIST command.

    Source:vade79
    Published:6 Sept 2003
    7.5
    High

    CVE-2003-0752

    Last Modified: 2 Dec 2012

    SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter.

    Source:frog
    Published:6 Sept 2003
    6.8
    Medium

    CVE-2003-0749

    Last Modified: 2 Dec 2012

    Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to insert arbitrary web script and steal cookies via the ~service parameter.

    Source:Martin Eiszner
    Published:6 Sept 2003
    5
    Medium

    CVE-2003-0748

    Last Modified: 2 Dec 2012

    Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the ~theme parameter and a ~template parameter with a filename followed by space characters, which can prevent SAP from effectively adding a .html extension to the filename.

    Source:Martin Eiszner
    Published:6 Sept 2003
    5
    Medium

    CVE-2003-0747

    Last Modified: 2 Dec 2012

    wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information such as directory structure and operating system via incorrect parameters (1) ~service, (2) ~templatelanguage, (3) ~language, (4) ~theme, or (5) ~template, which leaks the information in the resulting error message.

    Source:Martin Eiszner
    Published:6 Sept 2003
    4.6
    Medium

    CVE-2003-0740

    Last Modified: 25 Feb 2016

    Stunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the Stunnel server.

    Source:Steve Grubb
    Published:3 Sept 2003
    6.8
    Medium

    CVE-2003-0736

    Last Modified: 29 Nov 2012

    Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter in the search, and (5) possibly other parameters in the calendar, fatcat, and pagemaster modules.

    Source:Lorenzo Hernandez Garcia-Hierro
    Published:4 Sept 2003
    7.5
    High

    CVE-2003-0735

    Last Modified: 29 Nov 2012

    SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year parameter.

    Source:Lorenzo Hernandez Garcia-Hierro
    Published:4 Sept 2003
    7.5
    High

    CVE-2003-0729

    Last Modified: 2 Dec 2012

    Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.

    Source:storm
    Published:3 Sept 2003