Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-0820

Published Dec 15, 2003

Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0821

Published Dec 15, 2003

Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0856

Published Dec 15, 2003

iproute 2.4.7 and earlier allows local users to cause a denial of service via spoofed messages as other users to the kernel netlink interface.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0932

Published Dec 15, 2003

Buffer overflow in omega-rpg 0.90 allows local users to execute arbitrary code via a long (1) command line or (2) environment variable.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0936

Published Dec 15, 2003

Symantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using AWHOST32.exe.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0937

Published Dec 15, 2003

SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descripto…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0938

Published Dec 15, 2003

vos24u.c in SAP database server (SAP DB) 7.4.03.27 and earlier allows local users to gain SYSTEM privileges via a malicious "NETAPI32.DLL" in the current working directory, which…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0939

Published Dec 15, 2003

eo420_GetStringFromVarPart in veo420.c for SAP database server (SAP DB) 7.4.03.27 and earlier may allow remote attackers to execute arbitrary code via a connect packet with a 256…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0940

Published Dec 15, 2003

Directory traversal vulnerability in sqlfopenc for web-tools in SAP DB before 7.4.03.30 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0941

Published Dec 15, 2003

web-tools in SAP DB before 7.4.03.30 allows remote attackers to access the Web Agent Administration pages and modify configuration via a direct request to waadmin.wa.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0942

Published Dec 15, 2003

Buffer overflow in Web Agent Administration service in web-tools for SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a long Name parameter to waadmin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0943

Published Dec 15, 2003

web-tools in SAP DB before 7.4.03.30 installs several services that are enabled by default, which could allow remote attackers to obtain potentially sensitive information or redir…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0944

Published Dec 15, 2003

Buffer overflow in the WAECHO default service in web-tools in SAP DB before 7.4.03.30 allows remote attackers to execute arbitrary code via a URL with a long requestURI.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0945

Published Dec 15, 2003

The Web Database Manager in web-tools for SAP DB before 7.4.03.30 generates predictable session IDs, which allows remote attackers to conduct unauthorized activities.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0946

Published Dec 15, 2003

Format string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote attackers to cause a denial of service and possib…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0948

Published Dec 15, 2003

Buffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0950

Published Dec 15, 2003

PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0951

Published Dec 15, 2003

Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain pri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0955

Published Dec 15, 2003

OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is n…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 1,527 CVEsPage 19 of 62