Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-0925

Published Dec 1, 2003

Buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed GTP MSISDN string.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0926

Published Dec 1, 2003

Ethereal 0.9.15 and earlier, and Tethereal, allows remote attackers to cause a denial of service (crash) via certain malformed (1) ISAKMP or (2) MEGACO packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0927

Published Dec 1, 2003

Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0933

Published Dec 1, 2003

Buffer overflow in conquest 7.2 and earlier may allow a local user to execute arbitrary code via a long environment variable.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0934

Published Dec 1, 2003

Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0935

Published Dec 1, 2003

Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1216

Published Nov 27, 2003

SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1084

Published Nov 24, 2003

Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1195

Published Nov 23, 2003

SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1059

Published Nov 20, 2003

Unknown vulnerability in the libraries for the PGX32 frame buffer in Solaris 2.5.1 and 2.6 through 9 allows local users to gain root access.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1411

Published Nov 17, 2003

Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1412

Published Nov 17, 2003

nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1568

Published Nov 17, 2003

OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via cer…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1569

Published Nov 17, 2003

gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0543

Published Nov 17, 2003

Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0544

Published Nov 17, 2003

OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL cli…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0545

Published Nov 17, 2003

Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a ce…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0662

Published Nov 17, 2003

Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document wit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0712

Published Nov 17, 2003

Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0714

Published Nov 17, 2003

The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP serv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 1,527 CVEsPage 21 of 62