Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-0848

Published Nov 17, 2003

Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0849

Published Nov 17, 2003

Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the R…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0850

Published Nov 17, 2003

The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0852

Published Nov 17, 2003

Format string vulnerability in send_message.c for Sylpheed-claws 0.9.4 through 0.9.6 allows remote SMTP servers to cause a denial of service (crash) in sylpheed via format strings…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0853

Published Nov 17, 2003

An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0854

Published Nov 17, 2003

ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0860

Published Nov 17, 2003

Buffer overflows in PHP before 4.3.3 have unknown impact and unknown attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0861

Published Nov 17, 2003

Integer overflows in (1) base64_encode and (2) the GD library for PHP before 4.3.3 have unknown impact and unknown attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0863

Published Nov 17, 2003

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0864

Published Nov 17, 2003

Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0865

Published Nov 17, 2003

Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0866

Published Nov 17, 2003

The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0870

Published Nov 17, 2003

Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of escaped characters in the server name.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0872

Published Nov 17, 2003

Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activities via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0874

Published Nov 17, 2003

Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0875

Published Nov 17, 2003

Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0894

Published Nov 17, 2003

Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command lin…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0896

Published Nov 17, 2003

The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0897

Published Nov 17, 2003

"Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control mes…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0898

Published Nov 17, 2003

IBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via a symlink attack on (1) db2job and (2) d…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0626

Published Nov 13, 2003

psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1144

Published Nov 4, 2003

Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1570

Published Nov 3, 2003

Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0542

Published Nov 3, 2003

Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (cra…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 551-575 of 1,527 CVEsPage 23 of 62