Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,948 CVEs tagged with CWE-201,639 Critical, 5,067 High, 5,716 Medium, 522 Low, 4 Unrated.

CVE-2003-0368

Published Feb 3, 2004

Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malformed IP packet with a 0xFF TCP option.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1025

Published Jan 20, 2004

Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1209

Published Dec 31, 2003

The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1350

Published Dec 31, 2003

List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1364

Published Dec 31, 2003

Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with e…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1365

Published Dec 31, 2003

The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (car…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1402

Published Dec 31, 2003

PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1403

Published Dec 31, 2003

foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1405

Published Dec 31, 2003

DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1416

Published Dec 31, 2003

BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1419

Published Dec 31, 2003

Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1425

Published Dec 31, 2003

guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1440

Published Dec 31, 2003

SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1441

Published Dec 31, 2003

Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1443

Published Dec 31, 2003

Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrate…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1444

Published Dec 31, 2003

Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1450

Published Dec 31, 2003

BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a malformed RPL_NAMREPLY numeric 353 message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1463

Published Dec 31, 2003

Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation pa…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-1471

Published Dec 31, 2003

MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1485

Published Dec 31, 2003

Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1487

Published Dec 31, 2003

Multiple "command injection" vulnerabilities in Phorum 3.4 through 3.4.2 allow remote attackers to execute arbitrary commands and modify the Phorum configuration files via the (1)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1488

Published Dec 31, 2003

The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect param…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 12,876-12,900 of 12,948 CVEsPage 516 of 518