7.5
    High

    CVE-2003-0514

    Last Modified: 1 Jan 2013

    Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.

    Source:Corsaire Limited
    Published:16 Mar 2004
    5
    Medium

    CVE-2003-0511

    Last Modified: 28 Nov 2012

    The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.

    Source:blackangels
    Published:29 Jul 2003
    7.5
    High

    CVE-2003-0510

    Last Modified: 20 Nov 2012

    Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.

    Source:V9
    Published:4 Jul 2003
    10
    Critical

    CVE-2003-0509

    Last Modified: 3 Jun 2013

    SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.

    Published:4 Jul 2003
    7.5
    High

    CVE-2003-0508

    Last Modified: 20 Nov 2012

    Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.

    Source:Paul Szabo
    Published:4 Jul 2003
    2.1
    Low

    CVE-2003-0501

    Last Modified: 18 Nov 2012

    The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.

    Source:IhaQueR
    Published:20 Jun 2003
    10
    Critical

    CVE-2003-0500

    Last Modified: 29 Aug 2017

    SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.

    Source:Spaine
    Published:4 Jul 2003
    7.2
    High

    CVE-2003-0497

    Last Modified: 20 Nov 2012

    Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and executing it via cuxs.

    Source:Larry W. Cashdollar
    Published:4 Jul 2003
    7.2
    High

    CVE-2003-0496

    Last Modified: 22 Nov 2012

    Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.

    Source:Maceo
    Published:10 Jul 2003
    4.3
    Medium

    CVE-2003-0495

    Last Modified: 17 Nov 2012

    Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.

    Source:gilbert vilvoorde
    Published:28 Jun 2003
    6.8
    Medium

    CVE-2003-0492

    Last Modified: 17 Nov 2012

    Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary web script via the Search parameter.

    Source:JeiAr
    Published:28 Jun 2003
    5.1
    Medium

    CVE-2003-0488

    Last Modified: 18 Nov 2012

    Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl module, or (2) the alias parameter in the do_map module.

    Source:David F.Madrid
    Published:28 Jun 2003
    7.5
    High

    CVE-2003-0487

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module.

    Source:David F.Madrid
    Published:28 Jun 2003
    5
    Medium

    CVE-2003-0486

    Last Modified: 10 Feb 2016

    SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.

    Source:Rick Patel
    Published:28 Jun 2003
    6.8
    Medium

    CVE-2003-0483

    Last Modified: 19 Nov 2012

    Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter to member.php or (2) the action parameter to buddy.php.

    Source:Knight Commander
    Published:28 Jun 2003
    7.5
    High

    CVE-2003-0482

    Last Modified: 19 Nov 2012

    TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded code via a request to the repository containing the code.

    Source:François SORIN
    Published:28 Jun 2003
    4.3
    Medium

    CVE-2003-0481

    Last Modified: 19 Nov 2012

    Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated using the msg parameter to file_select.php.

    Source:François SORIN
    Published:28 Jun 2003
    10
    Critical

    CVE-2003-0478

    Last Modified: 20 Nov 2012

    Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.

    Source:Dinos
    Published:28 Jun 2003
    7.5
    High

    CVE-2003-0471

    Last Modified: 9 Mar 2011

    Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.

    Source:Metasploit
    Published:28 Jun 2003
    7.5
    High

    CVE-2003-0470

    Last Modified: 18 Nov 2012

    Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security Check service, allows remote attackers to execute arbitrary code via a long argument to CompareVersionStrings.

    Source:Cesar Cerrudo
    Published:28 Jun 2003
    7.5
    High

    CVE-2003-0469

    Last Modified: 19 Nov 2012

    Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.

    Source:Digital Scream
    Published:28 Jun 2003
    9.8
    Critical

    CVE-2003-0466

    Last Modified: 28 Nov 2012

    Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

    Published:31 Jul 2003
    1.2
    Low

    CVE-2003-0462

    Last Modified: 20 Nov 2012

    A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).

    Source:IhaQueR
    Published:25 Jul 2003
    7.2
    High

    CVE-2003-0454

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.

    Source:c0wboy
    Published:4 Jul 2003
    4.6
    Medium

    CVE-2003-0449

    Last Modified: 17 Nov 2012

    Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.

    Source:kf
    Published:20 Jun 2003
    5.1
    Medium

    CVE-2003-0447

    Last Modified: 17 Nov 2012

    The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via an argument to shdocvw.dll that causes a "javascript:" link to be generated.

    Source:GreyMagic Software
    Published:20 Jun 2003
    4.3
    Medium

    CVE-2003-0446

    Last Modified: 17 Nov 2012

    Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows remote attackers to insert arbitrary web script via an XML file that contains a parse error, which inserts the script in the resulting error message.

    Source:GreyMagic Software
    Published:20 Jun 2003
    4.3
    Medium

    CVE-2003-0442

    Last Modified: 14 Nov 2012

    Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.

    Source:Sverre H. Huseby
    Published:11 May 2003
    7.5
    High

    CVE-2003-0437

    Last Modified: 10 Feb 2016

    Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.

    Source:pokleyzz
    Published:20 Jun 2003
    7.5
    High

    CVE-2003-0436

    Last Modified: 16 Nov 2012

    Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.

    Source:pokleyzz
    Published:20 Jun 2003
    7.5
    High

    CVE-2003-0434

    Last Modified: 17 Nov 2012

    Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.

    Source:Martyn Gilmore
    Published:13 Jun 2003
    6.8
    Medium

    CVE-2003-0416

    Last Modified: 13 Nov 2012

    Cross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1) the year parameter in a showmonth action, (2) the month parameter in a showmonth action, or (3) the host parameter in a showhost action.

    Source:silent needel
    Published:11 Jun 2003
    6.8
    Medium

    CVE-2003-0413

    Last Modified: 13 Nov 2012

    Cross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows 2000/XP or (2) Sun Java System Web Server 6.1 allows remote attackers to insert arbitrary web script or HTML via an HTTP request that generates an "Invalid JSP file" error, which inserts the text in the resulting error message.

    Source:SPI Labs
    Published:11 Jun 2003
    7.5
    High

    CVE-2003-0411

    Last Modified: 13 Nov 2012

    Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.

    Source:SPI Labs
    Published:11 Jun 2003
    10
    Critical

    CVE-2003-0409

    Last Modified: 12 Nov 2012

    Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.

    Source:euronymous
    Published:11 Jun 2003
    7.2
    High

    CVE-2003-0408

    Last Modified: 13 Nov 2012

    Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.

    Source:Gino Thomas
    Published:11 Jun 2003
    10
    Critical

    CVE-2003-0407

    Last Modified: 13 Nov 2012

    Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.

    Source:wsxz
    Published:11 Jun 2003
    4.3
    Medium

    CVE-2003-0404

    Last Modified: 12 Nov 2012

    Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login template.

    Source:Ramon Pinuaga Cascales
    Published:11 Jun 2003
    5
    Medium

    CVE-2003-0400

    Last Modified: 4 Nov 2012

    Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.

    Source:@stake
    Published:11 Jun 2003
    4.6
    Medium

    CVE-2003-0396

    Last Modified: 7 Nov 2012

    Buffer overflow in les for ATM on Linux (linux-atm) before 2.4.1, if used setuid, allows local users to gain privileges via a long -f command line argument.

    Source:Angelo Rosiello
    Published:10 Jun 2003
    7.5
    High

    CVE-2003-0395

    Last Modified: 12 Nov 2012

    Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.

    Source:euronymous
    Published:10 Jun 2003
    7.5
    High

    CVE-2003-0394

    Last Modified: 12 Nov 2012

    objects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to malicious code on an attacker-controlled web site.

    Source:Over_G
    Published:10 Jun 2003
    7.5
    High

    CVE-2003-0391

    Last Modified: 4 Oct 2017

    Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.

    Source:ThreaT
    Published:10 Jun 2003
    4.6
    Medium

    CVE-2003-0390

    Last Modified: 15 Nov 2017

    Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local users to execute arbitrary code via long command line options that are fed into macros such as opt_warn_2, as used in functions such as opt_atoi.

    Source:kf
    Published:10 Jun 2003
    4.6
    Medium

    CVE-2003-0388

    Last Modified: 17 Nov 2012

    pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.

    Source:Karol Wiesek
    Published:16 Jun 2003
    7.2
    High

    CVE-2003-0385

    Last Modified: 15 Nov 2017

    Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.

    Published:10 Jun 2003
    7.5
    High

    CVE-2003-0380

    Last Modified: 4 Dec 2016

    Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.

    Source:gunzip
    Published:10 Jun 2003
    7.5
    High

    CVE-2003-0377

    Last Modified: 12 Nov 2012

    SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.

    Source:Gyrniff
    Published:6 Jun 2003
    5
    Medium

    CVE-2003-0376

    Last Modified: 13 Dec 2012

    Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code via an Attachment Converted argument with a large number of . (dot) characters.

    Source:Paul Szabo
    Published:6 Jun 2003
    4.3
    Medium

    CVE-2003-0375

    Last Modified: 12 Nov 2012

    Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary HTML and web script via the "member" parameter.

    Source:Marc Ruef
    Published:6 Jun 2003