4.6
    Medium

    CVE-2003-0372

    Last Modified: 12 Nov 2012

    Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.

    Source:Sir Mordred
    Published:6 Jun 2003
    7.5
    High

    CVE-2003-0371

    Last Modified: 12 Nov 2012

    Buffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP banner.

    Source:DHGROUP
    Published:6 Jun 2003
    4.6
    Medium

    CVE-2003-0358

    Last Modified: 25 Oct 2012

    Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.

    Source:tsao@efnet
    Published:30 May 2003
    7.5
    High

    CVE-2003-0352

    Last Modified: 6 Mar 2011

    Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.

    Source:Metasploit
    Published:17 Jul 2003
    7.5
    High

    CVE-2003-0349

    Last Modified: 7 Mar 2011

    Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.

    Source:Metasploit
    Published:28 Jun 2003
    10
    Critical

    CVE-2003-0347

    Last Modified: 2 Dec 2012

    Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.

    Source:eEye Digital Security Team
    Published:4 Sept 2003
    7.5
    High

    CVE-2003-0344

    Last Modified: 10 Feb 2016

    Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.

    Source:alumni
    Published:6 Jun 2003
    7.5
    High

    CVE-2003-0339

    Last Modified: 4 Dec 2016

    Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.

    Source:Xpl017Elz
    Published:22 May 2003
    5
    Medium

    CVE-2003-0338

    Last Modified: 11 Nov 2012

    Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.

    Source:dong-h0un U
    Published:21 May 2003
    5
    Medium

    CVE-2003-0336

    Last Modified: 16 Jul 2012

    Qualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a spoofed "Attachment Converted:" string, which is not properly handled by Eudora.

    Source:Bennett Haselton
    Published:22 May 2003
    7.6
    High

    CVE-2003-0332

    Last Modified: 11 Nov 2012

    The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.

    Source:mattmurphy
    Published:22 May 2003
    7.5
    High

    CVE-2003-0328

    Last Modified: 13 Dec 2012

    EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via a CTCP request from a large nickname, which causes an incorrect length calculation.

    Source:Li0n7
    Published:22 May 2003
    4.6
    Medium

    CVE-2003-0325

    Last Modified: 11 Nov 2012

    Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.

    Source:Luca Ercoli
    Published:22 May 2003
    7.5
    High

    CVE-2003-0320

    Last Modified: 11 Nov 2012

    header.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1" and modifying the admin_root parameter to point to a URL that contains a Trojan horse header.inc.php script.

    Published:22 May 2003
    7.5
    High

    CVE-2003-0317

    Last Modified: 11 Nov 2012

    iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.

    Source:iDefense
    Published:23 May 2003
    7.5
    High

    CVE-2003-0315

    Last Modified: 29 Sept 2016

    Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.

    Source:euronymous
    Published:17 May 2003
    6.4
    Medium

    CVE-2003-0314

    Last Modified: 10 Nov 2012

    Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence.

    Source:euronymous
    Published:17 May 2003
    6.4
    Medium

    CVE-2003-0312

    Last Modified: 10 Nov 2012

    Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.

    Source:euronymous
    Published:17 May 2003
    6.8
    Medium

    CVE-2003-0310

    Last Modified: 10 Nov 2012

    Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

    Source:Ferruh Mavituna
    Published:17 May 2003
    7.5
    High

    CVE-2003-0309

    Last Modified: 13 Sept 2016

    Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."

    Source:Marek Bialoglowy
    Published:17 May 2003
    7.2
    High

    CVE-2003-0306

    Last Modified: 4 Oct 2017

    Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.

    Source:einstein
    Published:17 May 2003
    10
    Critical

    CVE-2003-0304

    Last Modified: 5 Jan 2017

    one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.

    Source:frog
    Published:17 May 2003
    5
    Medium

    CVE-2003-0303

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.

    Source:frog
    Published:17 May 2003
    6.8
    Medium

    CVE-2003-0295

    Last Modified: 10 Nov 2012

    Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.

    Source:Ferruh Mavituna
    Published:15 May 2003
    5
    Medium

    CVE-2003-0293

    Last Modified: 10 Nov 2012

    PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.

    Source:Shaun Colley
    Published:15 May 2003
    5
    Medium

    CVE-2003-0290

    Last Modified: 9 Nov 2012

    Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.

    Source:Matthew Murphy
    Published:14 May 2003
    7.2
    High

    CVE-2003-0289

    Last Modified: 10 Nov 2012

    Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.

    Source:CMN
    Published:14 May 2003
    6.8
    Medium

    CVE-2003-0283

    Last Modified: 9 Nov 2012

    Cross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a message with a "<<" before a tag name in the (1) subject, (2) author's name, or (3) author's e-mail.

    Source:WiciU
    Published:14 May 2003
    2.6
    Low

    CVE-2003-0282

    Last Modified: 12 Nov 2012

    Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.

    Source:Jelmer
    Published:9 May 2003
    4.6
    Medium

    CVE-2003-0281

    Last Modified: 10 Feb 2016

    Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.

    Source:bob
    Published:14 May 2003
    10
    Critical

    CVE-2003-0280

    Last Modified: 9 Nov 2012

    Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.

    Source:Dennis Rand
    Published:14 May 2003
    6.8
    Medium

    CVE-2003-0278

    Last Modified: 9 Nov 2012

    Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

    Source:Julio Cesar
    Published:14 May 2003
    5
    Medium

    CVE-2003-0277

    Last Modified: 10 Nov 2012

    Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter.

    Source:Julio Cesar
    Published:14 May 2003
    5
    Medium

    CVE-2003-0276

    Last Modified: 10 Feb 2016

    Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET request with a large number of / characters.

    Source:aT4r
    Published:14 May 2003
    10
    Critical

    CVE-2003-0274

    Last Modified: 9 Nov 2012

    Buffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK value.

    Source:kf
    Published:9 May 2003
    7.2
    High

    CVE-2003-0269

    Last Modified: 8 Nov 2012

    Buffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.

    Source:Knud Erik Hojgaard
    Published:8 May 2003
    6.2
    Medium

    CVE-2003-0265

    Last Modified: 7 Nov 2012

    Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid bits, which allows local attackers to gain root privileges by modifying the files before the permissions are changed.

    Source:Larry W. Cashdollar
    Published:8 May 2003
    7.5
    High

    CVE-2003-0264

    Last Modified: 13 Jul 2017

    Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.

    Source:muts
    Published:8 May 2003
    7.5
    High

    CVE-2003-0263

    Last Modified: 8 Nov 2012

    Multiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.

    Source:Dennis Rand
    Published:8 May 2003
    7.2
    High

    CVE-2003-0262

    Last Modified: 15 Nov 2017

    leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.

    Source:gunzip
    Published:8 May 2003
    5
    Medium

    CVE-2003-0245

    Last Modified: 22 Nov 2017

    Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.

    Source:Matthew Murphy
    Published:28 May 2003
    7.5
    High

    CVE-2003-0243

    Last Modified: 9 Nov 2012

    Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts.

    Source:Revin Aldi
    Published:9 May 2003
    10
    Critical

    CVE-2003-0240

    Last Modified: 11 Nov 2012

    The web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and modify configuration via an HTTP request to the admin/admin.shtml containing a leading // (double slash).

    Source:Juliano Rizzo
    Published:30 May 2003
    7.2
    High

    CVE-2003-0232

    Last Modified: 6 Mar 2019

    Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.

    Source:refdom
    Published:25 Jul 2003
    5
    Medium

    CVE-2003-0231

    Last Modified: 27 Nov 2012

    Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.

    Source:refdom
    Published:25 Jul 2003
    7.5
    High

    CVE-2003-0228

    Last Modified: 9 Nov 2012

    Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.

    Source:Jelmer Kuperus
    Published:8 May 2003
    5
    Medium

    CVE-2003-0227

    Last Modified: 22 Nov 2017

    The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.

    Source:anonymous
    Published:30 May 2003
    5
    Medium

    CVE-2003-0226

    Last Modified: 13 Nov 2012

    Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.

    Source:Neo1
    Published:30 May 2003
    9
    Critical

    CVE-2003-0222

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute arbitrary code via a "CREATE DATABASE LINK" query containing a connect string with a long USING parameter.

    Published:30 Apr 2003
    7.5
    High

    CVE-2003-0220

    Last Modified: 2 Nov 2012

    Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.

    Source:Core Security
    Published:29 Apr 2003