2.1
    Low

    CVE-2003-0727

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.

    Source:y0
    Published:3 Sept 2003
    5.1
    Medium

    CVE-2003-0726

    Last Modified: 1 Dec 2012

    RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.

    Source:KrazySnake
    Published:3 Sept 2003
    7.5
    High

    CVE-2003-0725

    Last Modified: 5 Dec 2016

    Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.

    Source:Johnny Cyberpunk
    Published:3 Sept 2003
    7.5
    High

    CVE-2003-0723

    Last Modified: 20 Nov 2012

    Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.

    Source:dodo
    Published:3 Sept 2003
    10
    Critical

    CVE-2003-0722

    Last Modified: 27 Oct 2016

    The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.

    Source:Metasploit
    Published:17 Sept 2003
    7.5
    High

    CVE-2003-0720

    Last Modified: 16 Apr 2026

    Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.

    Source:sorbo
    Published:10 Sept 2003
    7.5
    High

    CVE-2003-0719

    Last Modified: 16 Apr 2026

    Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.

    Source:Johnny Cyberpunk
    Published:16 Apr 2004
    5
    Medium

    CVE-2003-0718

    Last Modified: 16 Apr 2026

    The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.

    Source:Amit Klein
    Published:16 Oct 2004
    7.5
    High

    CVE-2003-0717

    Last Modified: 16 Apr 2026

    The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

    Source:VeNoMouS
    Published:17 Oct 2003
    7.5
    High

    CVE-2003-0714

    Last Modified: 16 Apr 2026

    The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.

    Source:H D Moore
    Published:17 Oct 2003
    5
    Medium

    CVE-2003-0706

    Last Modified: 3 Dec 2012

    Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).

    Source:jsk
    Published:12 Sept 2003
    7.5
    High

    CVE-2003-0705

    Last Modified: 3 Dec 2012

    Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.

    Source:V9
    Published:12 Sept 2003
    7.5
    High

    CVE-2003-0701

    Last Modified: 25 Feb 2016

    Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.

    Source:malware
    Published:22 Aug 2003
    7.5
    High

    CVE-2003-0686

    Last Modified: 16 Nov 2017

    Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.

    Source:vertex
    Published:26 Aug 2003
    7.5
    High

    CVE-2003-0681

    Last Modified: 22 Nov 2017

    A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.

    Source:Gyan Chawdhary
    Published:17 Sept 2003
    7.5
    High

    CVE-2003-0666

    Last Modified: 22 Jan 2013

    Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.

    Source:valgasu
    Published:4 Sept 2003
    7.5
    High

    CVE-2003-0665

    Last Modified: 2 Dec 2012

    Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.

    Source:Oliver Lavery
    Published:4 Sept 2003
    7.2
    High

    CVE-2003-0659

    Last Modified: 9 Dec 2012

    Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.

    Source:Brett Moore
    Published:17 Oct 2003
    7.2
    High

    CVE-2003-0655

    Last Modified: 28 Nov 2012

    rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as a command line argument, which is modified while rscsi is running with privileges.

    Source:Secure Network Operations
    Published:5 Aug 2003
    7.5
    High

    CVE-2003-0651

    Last Modified: 31 Jan 2017

    Buffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:Carl Livitt
    Published:5 Aug 2003
    7.2
    High

    CVE-2003-0649

    Last Modified: 29 Nov 2012

    Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.

    Source:r-code
    Published:14 Aug 2003
    7.5
    High

    CVE-2003-0647

    Last Modified: 16 Apr 2026

    Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.

    Source:FX
    Published:5 Aug 2003
    4.6
    Medium

    CVE-2003-0645

    Last Modified: 7 Mar 2019

    man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.

    Source:vade79
    Published:14 Aug 2003
    7.5
    High

    CVE-2003-0625

    Last Modified: 27 Nov 2012

    Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake, which leaks the memory in the server's response.

    Source:V9
    Published:1 Aug 2003
    4.3
    Medium

    CVE-2003-0624

    Last Modified: 12 Dec 2012

    Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.

    Source:Corsaire Limited
    Published:5 Nov 2003
    5
    Medium

    CVE-2003-0621

    Last Modified: 11 Dec 2012

    The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.

    Source:Corsaire Limited
    Published:5 Nov 2003
    4.6
    Medium

    CVE-2003-0620

    Last Modified: 28 Nov 2012

    Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a long MANPATH environment variable, or (5) a long PATH environment variable.

    Source:V9
    Published:1 Aug 2003
    5
    Medium

    CVE-2003-0619

    Last Modified: 4 Sept 2016

    Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.

    Source:Jared Stanbrough
    Published:29 Jul 2003
    4.3
    Medium

    CVE-2003-0614

    Last Modified: 28 Nov 2012

    Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.

    Source:Larry Nguyen
    Published:1 Aug 2003
    4.6
    Medium

    CVE-2003-0611

    Last Modified: 25 Feb 2016

    Multiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line argument or (2) XTOKKAETAMADIR environment variable.

    Source:brahma
    Published:1 Aug 2003
    7.2
    High

    CVE-2003-0609

    Last Modified: 21 Apr 2017

    Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.

    Source:Marco Ivaldi
    Published:1 Aug 2003
    7.5
    High

    CVE-2003-0605

    Last Modified: 16 Apr 2026

    The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.

    Source:Flashsky
    Published:29 Jul 2003
    7.5
    High

    CVE-2003-0595

    Last Modified: 26 Nov 2012

    Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserReference.

    Source:Next Generation Software
    Published:25 Jul 2003
    7.1
    High

    CVE-2003-0590

    Last Modified: 25 Nov 2012

    Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon (image_subject) field.

    Source:Lethalman
    Published:18 Aug 2003
    7.5
    High

    CVE-2003-0586

    Last Modified: 26 Nov 2012

    Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to settings.inc.php.

    Source:Bosen
    Published:18 Aug 2003
    7.2
    High

    CVE-2003-0584

    Last Modified: 26 Nov 2012

    Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.

    Source:DVDMAN
    Published:18 Aug 2003
    4.6
    Medium

    CVE-2003-0579

    Last Modified: 15 Nov 2017

    uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.

    Source:kf
    Published:17 Jul 2003
    7.8
    High

    CVE-2003-0567

    Last Modified: 4 Oct 2017

    Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.

    Source:Martin Kluge
    Published:25 Jul 2003
    5
    Medium

    CVE-2003-0562

    Last Modified: 27 Nov 2012

    Buffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service (ABEND) via a long input string.

    Source:Uffe Nielsen
    Published:25 Jul 2003
    7.5
    High

    CVE-2003-0561

    Last Modified: 22 Nov 2012

    Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.

    Source:inv[at]dtors
    Published:15 Jul 2003
    10
    Critical

    CVE-2003-0560

    Last Modified: 22 Nov 2012

    SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.

    Source:TioEuy & AresU
    Published:15 Jul 2003
    7.5
    High

    CVE-2003-0558

    Last Modified: 10 Mar 2011

    Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.

    Source:Metasploit
    Published:15 Jul 2003
    7.5
    High

    CVE-2003-0557

    Last Modified: 30 May 2013

    SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.

    Source:G00db0y
    Published:15 Jul 2003
    5
    Medium

    CVE-2003-0543

    Last Modified: 19 Sept 2016

    Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.

    Source:Bram Matthys
    Published:30 Sept 2003
    5
    Medium

    CVE-2003-0540

    Last Modified: 2 Jan 2014

    The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.

    Source:r3b00t
    Published:3 Aug 2003
    3.6
    Low

    CVE-2003-0536

    Last Modified: 3 Nov 2012

    Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters.

    Source:Albert Puigsech Galicia
    Published:10 Jul 2003
    7.5
    High

    CVE-2003-0533

    Last Modified: 7 Mar 2011

    Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

    Source:Metasploit
    Published:16 Apr 2004
    6.8
    Medium

    CVE-2003-0526

    Last Modified: 26 Nov 2012

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."

    Source:Brett Moore
    Published:17 Jul 2003
    6.8
    Medium

    CVE-2003-0523

    Last Modified: 21 Nov 2012

    Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web script via the message parameter.

    Source:atomix
    Published:10 Jul 2003
    6.8
    Medium

    CVE-2003-0521

    Last Modified: 21 Nov 2012

    Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator privileges via script in a URL that is logged but not properly quoted when displayed via the (1) Error Log or (2) Latest Visitors screens.

    Source:Ory Segal
    Published:10 Jul 2003