Skip to main content

Year archive

CVEs published in 2003

Archive summary

1,527 CVEs published in 2003 — 138 Critical, 545 High, 747 Medium, 97 Low, 0 Unrated.

CVE-2003-0665

Published Oct 20, 2003

Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0666

Published Oct 20, 2003

Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0686

Published Oct 20, 2003

Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0689

Published Oct 20, 2003

The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a memb…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0702

Published Oct 20, 2003

Unknown vulnerability in an ISAPI plugin for ISS Server Sensor 7.0 XPU 20.16, 20.18, and possibly other versions before 20.19, allows remote attackers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0707

Published Oct 20, 2003

Buffer overflow in LinuxNode (node) before 0.3.2 allows remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0708

Published Oct 20, 2003

Format string vulnerability in LinuxNode (node) before 0.3.2 may allow attackers to cause a denial of service or execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0709

Published Oct 20, 2003

Buffer overflow in the whois client, which is not setuid but is sometimes called from within CGI programs, may allow remote attackers to execute arbitrary code via a long command…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0723

Published Oct 20, 2003

Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0724

Published Oct 20, 2003

ssh on HP Tru64 UNIX 5.1B and 5.1A does not properly handle RSA signatures when digital certificates and RSA keys are used, which could allow local and remote attackers to gain pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0727

Published Oct 20, 2003

Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of service or hijack user sessions.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-0728

Published Oct 20, 2003

Horde before 2.2.4 allows remote malicious web sites to steal session IDs and read or create arbitrary email by stealing the ID from a referrer URL.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0729

Published Oct 20, 2003

Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0730

Published Oct 20, 2003

Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0734

Published Oct 20, 2003

Unknown vulnerability in the pam_filter mechanism in pam_ldap before version 162, when LDAP based authentication is being used, allows users to bypass host-based access restrictio…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0735

Published Oct 20, 2003

SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year paramet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0736

Published Oct 20, 2003

Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calenda…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0737

Published Oct 20, 2003

The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime(…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0738

Published Oct 20, 2003

The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 626-650 of 1,527 CVEsPage 26 of 62