Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-0960

Published Dec 15, 2003

OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0961

Published Dec 15, 2003

Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0967

Published Dec 15, 2003

rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0968

Published Dec 15, 2003

Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long Us…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0970

Published Dec 15, 2003

The Network Management Port on Sun Fire B1600 systems allows remote attackers to cause a denial of service (packet loss) via ARP packets, which cause all ports to become temporari…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0971

Published Dec 15, 2003

GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0972

Published Dec 15, 2003

Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large number of ";" (semicolon) cha…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0973

Published Dec 15, 2003

Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0976

Published Dec 15, 2003

NFS Server (XNFS.NLM) for Novell NetWare 6.5 does not properly enforce sys:\etc\exports when hostname aliases from sys:etc\hosts file are used, which could allow users to mount fi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1056

Published Dec 11, 2003

The ed editor for Sun Solaris 2.6, 7, and 8 allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1057

Published Dec 8, 2003

Unknown vulnerability in CDE Print Viewer (dtprintinfo) for Sun Solaris 2.6 through 9 may allow local users to execute arbitrary code.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1058

Published Dec 3, 2003

The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or over…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0565

Published Dec 1, 2003

Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.…

CVSS 5.0 · Medium

CVE-2003-0621

Published Dec 1, 2003

The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argume…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0622

Published Dec 1, 2003

The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0623

Published Dec 1, 2003

Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argume…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0624

Published Dec 1, 2003

Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0788

Published Dec 1, 2003

Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "bu…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0834

Published Dec 1, 2003

Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEAR…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0886

Published Dec 1, 2003

Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 476-500 of 1,527 CVEsPage 20 of 62