Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-0786

Published Nov 17, 2003

The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0787

Published Nov 17, 2003

The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0792

Published Nov 17, 2003

Fetchmail 6.2.4 and earlier does not properly allocate memory for long lines, which allows remote attackers to cause a denial of service (crash) via a certain email.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0793

Published Nov 17, 2003

GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0794

Published Nov 17, 2003

GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0809

Published Nov 17, 2003

Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0830

Published Nov 17, 2003

Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0831

Published Nov 17, 2003

ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote attackers to execute arbitrary code via a…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0832

Published Nov 17, 2003

Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0833

Published Nov 17, 2003

Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0835

Published Nov 17, 2003

Multiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header with a long hostname.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0836

Published Nov 17, 2003

Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 before Fixpak 10 and 10a, and 8.1 before Fixpak 2, allows attackers with "Connect" privileges to execute arbitrary c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0837

Published Nov 17, 2003

Stack-based buffer overflow in IBM DB2 Universal Data Base 7.2 for Windows, before Fixpak 10a, allows attackers with "Connect" privileges to execute arbitrary code via the INVOKE…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0838

Published Nov 17, 2003

Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0839

Published Nov 17, 2003

Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0840

Published Nov 17, 2003

Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0841

Published Nov 17, 2003

The grid option in PeopleSoft 8.42 stores temporary .xls files in guessable directories under the web document root, which allows remote attackers to steal search results by direc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0842

Published Nov 17, 2003

Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to exe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0843

Published Nov 17, 2003

Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allow…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0844

Published Nov 17, 2003

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0845

Published Nov 17, 2003

Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unaut…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0846

Published Nov 17, 2003

SuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on the .java_wrapper temporary file.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0847

Published Nov 17, 2003

SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 1,527 CVEsPage 22 of 62