Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-0683

Published Nov 3, 2003

NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0789

Published Nov 3, 2003

mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0855

Published Nov 3, 2003

Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0871

Published Nov 3, 2003

Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0876

Published Nov 3, 2003

Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (copied) from a mounted volume such as a disk image (DMG), wh…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0877

Published Nov 3, 2003

Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictab…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0878

Published Nov 3, 2003

slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2003-0875.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0880

Published Nov 3, 2003

Unknown vulnerability in Mac OS X before 10.3 allows local users to access Dock functions from behind Screen Effects when Full Keyboard Access is enabled using the Keyboard pane i…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0881

Published Nov 3, 2003

Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0882

Published Nov 3, 2003

Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0883

Published Nov 3, 2003

The System Preferences capability in Mac OS X before 10.3 allows local users to access secure Preference Panes for a short period after an administrator has authenticated to the s…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0895

Published Nov 3, 2003

Buffer overflow in the Mac OS X kernel 10.2.8 and earlier allows local users, and possibly remote attackers, to cause a denial of service (crash), access portions of memory, and p…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0899

Published Nov 3, 2003

Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0901

Published Nov 3, 2003

Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1145

Published Nov 3, 2003

Cross-site scripting (XSS) vulnerability in friendmail.php in OpenAutoClassifieds 1.0 allows remote attackers to inject arbitrary web script or HTML via the listing parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1182

Published Nov 3, 2003

Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1184

Published Nov 3, 2003

Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1185

Published Nov 3, 2003

Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) An…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1190

Published Nov 3, 2003

Cross-site scripting (XSS) vulnerability in PHPRecipeBook 1.24 through 2.17 allows remote attackers to inject arbitrary web script or HTML via a recipe.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1192

Published Nov 3, 2003

Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1193

Published Nov 3, 2003

Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1196

Published Nov 3, 2003

SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1187

Published Nov 2, 2003

Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1188

Published Nov 2, 2003

Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 576-600 of 1,527 CVEsPage 24 of 62