Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-0249

Published Dec 31, 2003

PHP treats unknown methods such as "PoSt" as a GET request, which could allow attackers to intended access restrictions if PHP is running on a server that passes on all methods, s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0317

Published Dec 31, 2003

iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0363

Published Dec 31, 2003

Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0627

Published Dec 31, 2003

psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername argume…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0857

Published Dec 31, 2003

The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interfac…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0885

Published Dec 31, 2003

Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0887

Published Dec 31, 2003

ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0900

Published Dec 31, 2003

Perl 5.8.1 on Fedora Core does not properly initialize the random number generator when forking, which makes it easier for attackers to predict random numbers.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0954

Published Dec 31, 2003

Buffer overflow in rcp for AIX 4.3.3, 5.1 and 5.2 allows local users to gain privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0956

Published Dec 31, 2003

Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to be returned from the disk when handling sparse files, or cau…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0959

Published Dec 31, 2003

Multiple integer overflows in the 32bit emulation for AMD64 architectures in Linux 2.4 kernel before 2.4.21 allows attackers to cause a denial of service or gain root privileges v…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0986

Published Dec 31, 2003

Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to k…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-1005

Published Dec 31, 2003

The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequences.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1066

Published Dec 31, 2003

Buffer overflow in the syslog daemon for Solaris 2.6 through 9 allows remote attackers to cause a denial of service (syslogd crash) and possibly execute arbitrary code via long sy…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1073

Published Dec 31, 2003

A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then mod…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-1076

Published Dec 31, 2003

Unknown vulnerability in sendmail for Solaris 7, 8, and 9 allows local users to cause a denial of service (unknown impact) and possibly gain privileges via certain constructs in a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1082

Published Dec 31, 2003

Buffer overflow in utmp_update for Solaris 2.6 through 9 allows local users to gain root privileges, as identified by Sun BugID 4705891, a different vulnerability than CVE-2003-10…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1083

Published Dec 31, 2003

Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1085

Published Dec 31, 2003

The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstable service) via a long GET request, po…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1087

Published Dec 31, 2003

Unknown vulnerability in diagmond and possibly other applications in HP9000 Series 700/800 running HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows remote attackers to cause a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1089

Published Dec 31, 2003

index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1091

Published Dec 31, 2003

Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1092

Published Dec 31, 2003

Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1093

Published Dec 31, 2003

BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user's password when it throws a ResourceAllocationExcept…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1094

Published Dec 31, 2003

BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial conte…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,527 CVEsPage 1 of 62