Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-1159

Published Oct 31, 2003

Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1143

Published Oct 30, 2003

Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1160

Published Oct 30, 2003

FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leadi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1194

Published Oct 30, 2003

Cross-site scripting (XSS) vulnerability in Booby .1 through 0.2.3 allows remote attackers to inject arbitrary web script or HTML via the error message.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1197

Published Oct 30, 2003

Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inject arbitrary web script or HTML via the (1) top_message pa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1186

Published Oct 29, 2003

Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1189

Published Oct 29, 2003

Unknown vulnerability in Nokia IPSO 3.7, configured as IP Clusters, allows remote attackers to cause a denial of service via unknown attack vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1191

Published Oct 29, 2003

chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML in the Name field, which prevents the main.php form from bei…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1151

Published Oct 28, 2003

Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1183

Published Oct 28, 2003

The WebCache component in Oracle Files 9.0.3.1.0, 9.0.3.2.0, and 9.0.3.3.0 of Oracle Collaboration Suite Release 1 caches files despite the cacheability rules imposed by Oracle Fi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1060

Published Oct 27, 2003

The NFS Server for Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (UFS panic) via certain invalid UFS requests, which triggers a null dereference.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1137

Published Oct 27, 2003

Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1138

Published Oct 27, 2003

The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1139

Published Oct 27, 2003

Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink attack on the resulting musicqueue.crash file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1140

Published Oct 27, 2003

Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1149

Published Oct 27, 2003

Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to inject arbitrary web script or HTML via a URL to a blocked s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1150

Published Oct 27, 2003

Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1148

Published Oct 25, 2003

Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allow…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1181

Published Oct 25, 2003

Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1136

Published Oct 23, 2003

Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Jav…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0630

Published Oct 20, 2003

Multiple buffer overflows in the atari800.svgalib setuid program of the Atari 800 emulator (atari800) before 1.2.2 allow local users to gain privileges via long command line argum…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0664

Published Oct 20, 2003

Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically exec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 601-625 of 1,527 CVEsPage 25 of 62