2003 CVE Vulnerabilities

1,555 CVEs published in 2003.

CVE IDSeverityCVSSDescription
CVE-2003-0784Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root priv...
CVE-2003-0805Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary ...
CVE-2003-0803Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the locat...
CVE-2003-0692KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, ...
CVE-2003-0690KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers t...
CVE-2003-0697Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows l...
CVE-2003-0695Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute ...
CVE-2003-1053Multiple buffer overflows in XShisen allow attackers to execute arbitrary code via a long (1) -KCONV command line option...
CVE-2003-0780Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers wit...
CVE-2003-0722The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attack...
CVE-2003-0768Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection f...
CVE-2003-0769Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to inse...
CVE-2003-0770FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains i...
CVE-2003-0771Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local...
CVE-2003-0772Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly e...
CVE-2003-0773saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT R...
CVE-2003-0774saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to caus...
CVE-2003-0775saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the...
CVE-2003-0776saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting...
CVE-2003-0777saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections,...
CVE-2003-0778saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain case...
CVE-2003-0779SQL injection vulnerability in the Call Detail Record (CDR) logging functionality for Asterisk allows remote attackers t...
CVE-2003-0693A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to exec...
CVE-2003-0763Cross-site scripting (XSS) vulnerability in Escapade Scripting Engine (ESP) allows remote attackers to inject arbitrary ...
CVE-2003-0706Unknown vulnerability in mah-jong 1.5.6 and earlier allows remote attackers to cause a denial of service (tight loop).

Check if your code is affected by 2003 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now