CVE-2003-0 to CVE-2003-999
288 CVEs with public proof-of-concept exploits.
- CVE-2003-00014 PoCsMultiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain…
- CVE-2003-00021 PoCCross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote…
- CVE-2003-00032 PoCsBuffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows…
- CVE-2003-00041 PoCBuffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long…
- CVE-2003-00091 PoCCross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary…
- CVE-2003-00152 PoCsDouble-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary…
- CVE-2003-00191 PoCuml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network…
- CVE-2003-00271 PoCDirectory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers…
- CVE-2003-00341 PoCBuffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute…
- CVE-2003-00382 PoCsCross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML into web pages via…
- CVE-2003-00421 PoCJakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or…
- CVE-2003-00502 PoCsparse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to…
- CVE-2003-00561 PoCBuffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or (2) -r command…
- CVE-2003-00781 PoCssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block…
- CVE-2003-00853 PoCsBuffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1,…
- CVE-2003-00871 PoCBuffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain…
- CVE-2003-00891 PoCBuffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a…
- CVE-2003-01003 PoCsBuffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a…
- CVE-2003-01012 PoCsminiserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and…
- CVE-2003-01022 PoCsBuffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly…
- CVE-2003-01073 PoCsBuffer overflow in the gzprintf function in zlib 1.1.4, when zlib is compiled without vsnprintf or when long inputs are truncated using…
- CVE-2003-01081 PoCisakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain…
- CVE-2003-010913 PoCsBuffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows…
- CVE-2003-01111 PoCThe ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer,…
- CVE-2003-01131 PoCBuffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an…
- CVE-2003-01171 PoCBuffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute…
- CVE-2003-01182 PoCsSQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows…
- CVE-2003-01211 PoCClearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specify a MIME-Version…
- CVE-2003-01241 PoCman before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf…
- CVE-2003-01251 PoCBuffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service…
- CVE-2003-01275 PoCsThe kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using…
- CVE-2003-01281 PoCThe try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a…
- CVE-2003-01291 PoCXimian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail…
- CVE-2003-01301 PoCThe handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML…
- CVE-2003-01324 PoCsA memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of…
- CVE-2003-01431 PoCThe pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could…
- CVE-2003-01443 PoCsBuffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other…
- CVE-2003-01501 PoCMySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO…
- CVE-2003-01531 PoCbonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2)…
- CVE-2003-01541 PoCCross-site scripting vulnerabilities (XSS) in bonsai Mozilla CVS query tool allow remote attackers to execute arbitrary web script via (1)…
- CVE-2003-01612 PoCsThe prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from…
- CVE-2003-01651 PoCFormat string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command…
- CVE-2003-01663 PoCsInteger signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service (memory…
- CVE-2003-01691 PoChpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU…
- CVE-2003-01711 PoCDirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to…
- CVE-2003-01723 PoCsBuffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote attackers to cause a…
- CVE-2003-01903 PoCsOpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist,…
- CVE-2003-01951 PoCCUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does…
- CVE-2003-020111 PoCsBuffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and…
- CVE-2003-02033 PoCsBuffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.
- CVE-2003-02092 PoCsInteger overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code…
- CVE-2003-02111 PoCMemory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected…
- CVE-2003-02138 PoCsctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1,…
- CVE-2003-02151 PoCSQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username…
- CVE-2003-02206 PoCsBuffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to…
- CVE-2003-02221 PoCStack-based buffer overflow in Oracle Net Services for Oracle Database Server 9i release 2 and earlier allows attackers to execute…
- CVE-2003-02262 PoCsMicrosoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request…
- CVE-2003-02271 PoCThe logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft…
- CVE-2003-02281 PoCDirectory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to…
- CVE-2003-02311 PoCMicrosoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long…
- CVE-2003-02321 PoCMicrosoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls…
- CVE-2003-02401 PoCThe web-based administration capability for various Axis Network Camera products allows remote attackers to bypass access restrictions and…
- CVE-2003-02432 PoCsHappycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter…
- CVE-2003-02451 PoCVulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote…
- CVE-2003-02621 PoCleksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting…
- CVE-2003-02632 PoCsMultiple buffer overflows in Floosietek FTGate Pro Mail Server (FTGatePro) 1.22 allow remote attackers to execute arbitrary code via long…
- CVE-2003-026413 PoCsMultiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to…
- CVE-2003-02651 PoCRace condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initializing the setuid…
- CVE-2003-02694 PoCsBuffer overflow in youbin allows local users to gain privileges via a long HOME environment variable.
- CVE-2003-02701 PoCThe administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for…
- CVE-2003-02711 PoCBuffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.
- CVE-2003-02741 PoCBuffer overflow in catmail for ListProc 8.2.09 and earlier allows remote attackers to execute arbitrary code via a long ULISTPROC_UMASK…
- CVE-2003-02762 PoCsBuffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GET…
- CVE-2003-02771 PoCDirectory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files…
- CVE-2003-02781 PoCCross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert…
- CVE-2003-02802 PoCsMultiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via…
- CVE-2003-02814 PoCsBuffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local…
- CVE-2003-02828 PoCsDirectory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot)…
- CVE-2003-02831 PoCCross-site scripting (XSS) vulnerability in Phorum before 3.4.3 allows remote attackers to inject arbitrary web script and HTML tags via a…
- CVE-2003-02892 PoCsFormat string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string…
- CVE-2003-02902 PoCsMemory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections,…
- CVE-2003-02931 PoCPalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.
- CVE-2003-02951 PoCCross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script…
- CVE-2003-03031 PoCSQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number…
- CVE-2003-03041 PoCone||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php…
- CVE-2003-03062 PoCsBuffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long…
- CVE-2003-03091 PoCInternet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web…
- CVE-2003-03101 PoCCross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.
- CVE-2003-03121 PoCDirectory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an…
- CVE-2003-03141 PoCSnowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence.
- CVE-2003-03151 PoCSnowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP…
- CVE-2003-03171 PoCiisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.
- CVE-2003-03201 PoCheader.php in ttCMS 2.3 and earlier allows remote attackers to inject arbitrary PHP code by setting the ttcms_user_admin parameter to "1"…
- CVE-2003-03255 PoCsBuffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line…
- CVE-2003-03281 PoCEPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service…
- CVE-2003-03301 PoCBuffer overflow in unknown versions of Maelstrom allows local users to execute arbitrary code via a long -player command line argument.
- CVE-2003-03321 PoCThe ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension…
- CVE-2003-03361 PoCQualcomm Eudora 5.2.1 allows remote attackers to read arbitrary files via an email message with a carriage return (CR) character in a…
- CVE-2003-03371 PoCThe ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the…
- CVE-2003-03381 PoCDirectory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files…
- CVE-2003-03392 PoCsMultiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long…
- CVE-2003-03445 PoCsBuffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash)…
- CVE-2003-03471 PoCHeap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote…
- CVE-2003-03494 PoCsBuffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft…
- CVE-2003-03525 PoCsBuffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to…
- CVE-2003-03586 PoCsBuffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to…
- CVE-2003-03711 PoCBuffer overflow in Prishtina FTP client 1.x allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2003-03721 PoCSigned integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of…
- CVE-2003-03752 PoCsCross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to insert arbitrary…
- CVE-2003-03761 PoCBuffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute…
- CVE-2003-03771 PoCSQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote…
- CVE-2003-03801 PoCBuffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of…
- CVE-2003-03851 PoCBuffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.
- CVE-2003-03881 PoCpam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and…
- CVE-2003-03902 PoCsMultiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, may allow local…
- CVE-2003-03911 PoCFormat string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of…
- CVE-2003-03941 PoCobjects.inc.php4 in BLNews 2.1.3 allows remote attackers to execute arbitrary PHP code via a Server[path] parameter that points to…
- CVE-2003-03951 PoCUltimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request…
- CVE-2003-03963 PoCsBuffer overflow in les for ATM on Linux (linux-atm) before 2.4.1, if used setuid, allows local users to gain privileges via a long -f…
- CVE-2003-04002 PoCsVignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized…
- CVE-2003-04041 PoCMultiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to…
- CVE-2003-04072 PoCsBuffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.
- CVE-2003-04081 PoCBuffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p…
- CVE-2003-04091 PoCBuffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2003-04111 PoCSun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase…
- CVE-2003-04131 PoCCross-site scripting (XSS) vulnerability in the webapps-simple sample application for (1) Sun ONE Application Server 7.0 for Windows…
- CVE-2003-04162 PoCsCross-site scripting (XSS) vulnerability in index.cgi for Bandmin 1.4 allows remote attackers to insert arbitrary HTML or script via (1)…
- CVE-2003-04341 PoCVarious PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell…
- CVE-2003-04362 PoCsBuffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.
- CVE-2003-04371 PoCBuffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.
- CVE-2003-04421 PoCCross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows…
- CVE-2003-04461 PoCCross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsoft products, allows…
- CVE-2003-04471 PoCThe Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in the Local Zone via…
- CVE-2003-04491 PoCProgress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via…
- CVE-2003-04541 PoCMultiple buffer overflows in xgalaga 2.0.34 and earlier allow local users to gain privileges via a long HOME environment variable.
- CVE-2003-04621 PoCA race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux…
- CVE-2003-04668 PoCsOff-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary…
- CVE-2003-04692 PoCsBuffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of…
- CVE-2003-04701 PoCBuffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the Symantec Security…
- CVE-2003-04716 PoCsBuffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a…
- CVE-2003-04781 PoCFormat string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1,…
- CVE-2003-04811 PoCMultiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script, as demonstrated…
- CVE-2003-04821 PoCTUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly accessing the uploaded…
- CVE-2003-04831 PoCCross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member…
- CVE-2003-04841 PoCCross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the…
- CVE-2003-04861 PoCSQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id…
- CVE-2003-04875 PoCsMultiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute…
- CVE-2003-04882 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via…
- CVE-2003-04921 PoCCross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to execute arbitrary…
- CVE-2003-04951 PoCCross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a news item.
- CVE-2003-04964 PoCsMicrosoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist…
- CVE-2003-04971 PoCCaché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying…
- CVE-2003-05001 PoCSQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers…
- CVE-2003-05011 PoCThe /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing…
- CVE-2003-05081 PoCBuffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute…
- CVE-2003-05093 PoCsSQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain…
- CVE-2003-05102 PoCsFormat string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.
- CVE-2003-05111 PoCThe web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a…
- CVE-2003-05141 PoCApple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot)…
- CVE-2003-05211 PoCCross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel…
- CVE-2003-05231 PoCCross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execute arbitrary web…
- CVE-2003-05261 PoCCross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to…
- CVE-2003-05335 PoCsStack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service…
- CVE-2003-05361 PoCDirectory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary…
- CVE-2003-05402 PoCsThe address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed…
- CVE-2003-05431 PoCInteger overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate…
- CVE-2003-05571 PoCSQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive…
- CVE-2003-05584 PoCsBuffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response to a PASV request.
- CVE-2003-05603 PoCsSQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.
- CVE-2003-05613 PoCsMultiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long…
- CVE-2003-05621 PoCBuffer overflow in the CGI2PERL.NLM PERL handler in Novell Netware 5.1 and 6.0 allows remote attackers to cause a denial of service…
- CVE-2003-05674 PoCsCisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence…
- CVE-2003-05771 PoCmpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate,…
- CVE-2003-05791 PoCuvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the…
- CVE-2003-05842 PoCsFormat string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to…
- CVE-2003-05861 PoCBrooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP request to…
- CVE-2003-05901 PoCCross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script via the post icon…
- CVE-2003-05951 PoCBuffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to…
- CVE-2003-06058 PoCsThe RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to…
- CVE-2003-06092 PoCsStack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long…
- CVE-2003-06111 PoCMultiple buffer overflows in xtokkaetama 1.0 allow local users to gain privileges via a long (1) -display command line argument or (2)…
- CVE-2003-06121 PoCMultiple buffer overflows in main.c for Crafty 19.3 allow local users to gain group "games" privileges via long command line arguments to…
- CVE-2003-06141 PoCCross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script…
- CVE-2003-06191 PoCInteger signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of…
- CVE-2003-06201 PoCMultiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1)…
- CVE-2003-06211 PoCThe Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root…
- CVE-2003-06241 PoCCross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject…
- CVE-2003-06251 PoCOff-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malformed client request…
- CVE-2003-06452 PoCsman-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which…
- CVE-2003-06471 PoCBuffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long…
- CVE-2003-06491 PoCBuffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
- CVE-2003-06511 PoCBuffer overflow in the mylo_log logging function for mod_mylo 0.2.1 and earlier allows remote attackers to execute arbitrary code via a…
- CVE-2003-06521 PoCBuffer overflow in xtokkaetama allows local users to gain privileges via a long -nickname command line argument, a different vulnerability…
- CVE-2003-06552 PoCsrscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file…
- CVE-2003-06592 PoCsBuffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1)…
- CVE-2003-06651 PoCBuffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to…
- CVE-2003-06663 PoCsBuffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data…
- CVE-2003-06811 PoCA "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3)…
- CVE-2003-06861 PoCBuffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute…
- CVE-2003-06932 PoCsA "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code…
- CVE-2003-06941 PoCThe prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated…
- CVE-2003-07011 PoCBuffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote…
- CVE-2003-07051 PoCBuffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.
- CVE-2003-07061 PoCUnknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).
- CVE-2003-07143 PoCsThe Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory…
- CVE-2003-07175 PoCsThe Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers…
- CVE-2003-07181 PoCThe WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service…
- CVE-2003-07193 PoCsBuffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft…
- CVE-2003-07201 PoCBuffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.
- CVE-2003-07211 PoCInteger signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an…
- CVE-2003-07225 PoCsThe default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof…
- CVE-2003-07232 PoCsBuffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
- CVE-2003-07251 PoCBuffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal…
- CVE-2003-07261 PoCRealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that…
- CVE-2003-07277 PoCsMultiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to cause a denial of…
- CVE-2003-07291 PoCBuffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.
- CVE-2003-07351 PoCSQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL…
- CVE-2003-07364 PoCsMultiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script…
- CVE-2003-07401 PoCStunnel 4.00, and 3.24 and earlier, leaks a privileged file descriptor returned by listen(), which allows local users to hijack the…
- CVE-2003-07471 PoCwgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensitive information…
- CVE-2003-07481 PoCDirectory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to read…
- CVE-2003-07491 PoCCross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to…
- CVE-2003-07521 PoCSQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass…
- CVE-2003-07552 PoCsBuffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating long directory…
- CVE-2003-07571 PoCCheck Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain…
- CVE-2003-07581 PoCBuffer overflow in db2dart in IBM DB2 Universal Data Base 7.2 before Fixpak 10 allows local users to gain root privileges via a long…
- CVE-2003-07591 PoCBuffer overflow in db2licm in IBM DB2 Universal Data Base 7.2 before Fixpak 10a allows local users to gain root privileges via a long…
- CVE-2003-07601 PoCBlubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.
- CVE-2003-07621 PoCBuffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL…
- CVE-2003-07631 PoCCross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary script via the…
- CVE-2003-07651 PoCThe IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a…
- CVE-2003-07662 PoCsMultiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute…
- CVE-2003-07671 PoCBuffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier…
- CVE-2003-07691 PoCCross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web…
- CVE-2003-07703 PoCsFUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains illegal characters,…
- CVE-2003-07721 PoCMultiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary…
- CVE-2003-07803 PoCsBuffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE…
- CVE-2003-07832 PoCsMultiple buffer overflows in hztty 2.0 allow local users to gain root privileges.
- CVE-2003-07951 PoCThe vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing…
- CVE-2003-08011 PoCCross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web…
- CVE-2003-08021 PoCNokia Electronic Documentation (NED) 5.0 allows remote attackers to obtain a directory listing of the WebLogic web root, and the physical…
- CVE-2003-08031 PoCNokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter,…
- CVE-2003-08052 PoCsMultiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a…
- CVE-2003-08091 PoCInternet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows…
- CVE-2003-08126 PoCsStack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute…
- CVE-2003-08131 PoCA multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a…
- CVE-2003-08162 PoCsInternet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a…
- CVE-2003-08184 PoCsMultiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and…
- CVE-2003-08223 PoCsBuffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote…
- CVE-2003-08263 PoCslsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c…
- CVE-2003-08301 PoCBuffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.
- CVE-2003-08315 PoCsProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, which allows remote…
- CVE-2003-08331 PoCStack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long…
- CVE-2003-08342 PoCsBuffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment…
- CVE-2003-08351 PoCMultiple buffer overflows in asf_http_request of MPlayer before 0.92 allows remote attackers to execute arbitrary code via an ASX header…
- CVE-2003-08381 PoCInternet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window…
- CVE-2003-08401 PoCBuffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long…
- CVE-2003-08421 PoCStack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in…
- CVE-2003-08451 PoCUnknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration,…
- CVE-2003-08462 PoCsSuSEconfig.javarunt in the javarunt package on SuSE Linux 7.3Pro allows local users to overwrite arbitrary files via a symlink attack on…
- CVE-2003-08473 PoCsSuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the…
- CVE-2003-08482 PoCsHeap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified…
- CVE-2003-08494 PoCsBuffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified…
- CVE-2003-08531 PoCAn integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary…
- CVE-2003-08541 PoCls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be…
- CVE-2003-08631 PoCThe php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir…
- CVE-2003-08641 PoCBuffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of service.
- CVE-2003-08652 PoCsHeap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a…
- CVE-2003-08661 PoCThe Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service…
- CVE-2003-08701 PoCHeap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a large number of…
- CVE-2003-08861 PoCFormat string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.
- CVE-2003-08961 PoCThe loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier…
- CVE-2003-08981 PoCIBM DB2 7.2 before FixPak 10a, and earlier versions including 7.1, allows local users to overwrite arbitrary files and gain privileges via…
- CVE-2003-08992 PoCsBuffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that…
- CVE-2003-09081 PoCThe Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary…
- CVE-2003-09101 PoCThe NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows…
- CVE-2003-09311 PoCSygate Enforcer 4.0 earlier allows remote attackers to cause a denial of service (service hang) by replaying a malformed discovery packet…
- CVE-2003-09361 PoCSymantec PCAnywhere 10.x and 11, when started as a service, allows attackers to gain SYSTEM privileges via the help interface using…
- CVE-2003-09461 PoCFormat string vulnerability in clamav-milter for Clam AntiVirus 0.60 through 0.60p, and other versions before 0.65, allows remote…
- CVE-2003-09474 PoCsBuffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.
- CVE-2003-09481 PoCBuffer overflow in iwconfig allows local users to execute arbitrary code via a long HOME environment variable.
- CVE-2003-09552 PoCsOpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a…
- CVE-2003-09612 PoCsInteger overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root…
- CVE-2003-09631 PoCBuffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute…
- CVE-2003-09671 PoCrad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string…
- CVE-2003-09742 PoCsApplied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as (1) add new users…
- CVE-2003-09854 PoCsThe mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly…
- CVE-2003-09902 PoCsThe parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via shell…