| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2003-1390 | 0.00 | — | 0.01 | Dec 31, 2003 | RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the passphrase. | |||
| CVE-2003-1391 | 0.00 | — | 0.01 | Dec 31, 2003 | RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers to guess the passphrase. | |||
| CVE-2003-1392 | 0.00 | — | 0.01 | Dec 31, 2003 | CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data. | |||
| CVE-2003-1393 | 0.00 | — | 0.03 | Dec 31, 2003 | Buffer overflow in Gupta SQLBase 8.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long EXECUTE command. | |||
| CVE-2003-1394 | 0.00 | — | 0.01 | Dec 31, 2003 | CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file. | |||
| CVE-2003-1395 | 0.00 | — | 0.04 | Dec 31, 2003 | Buffer overflow in KaZaA Media Desktop 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a response to the ad server. | |||
| CVE-2003-1396 | 0.04 | — | 0.09 | Dec 31, 2003 | Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension. | |||
| CVE-2003-1397 | 0.03 | — | 0.06 | Dec 31, 2003 | The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method. | |||
| CVE-2003-1398 | 0.00 | — | 0.02 | Dec 31, 2003 | Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification). | |||
| CVE-2003-1399 | 0.00 | — | 0.00 | Dec 31, 2003 | eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information. | |||
| CVE-2003-1400 | 0.03 | — | 0.01 | Dec 31, 2003 | Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter. | |||
| CVE-2003-1401 | 0.03 | — | 0.02 | Dec 31, 2003 | login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request. | |||
| CVE-2003-1402 | 0.00 | — | 0.02 | Dec 31, 2003 | PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015. | |||
| CVE-2003-1403 | 0.00 | — | 0.01 | Dec 31, 2003 | foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | |||
| CVE-2003-1404 | 0.00 | — | 0.01 | Dec 31, 2003 | DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords. | |||
| CVE-2003-1405 | 0.03 | — | 0.04 | Dec 31, 2003 | DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3. | |||
| CVE-2003-1406 | 0.03 | — | 0.03 | Dec 31, 2003 | PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3. | |||
| CVE-2003-1407 | 0.03 | — | 0.03 | Dec 31, 2003 | Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command. | |||
| CVE-2003-1408 | 0.00 | — | 0.01 | Dec 31, 2003 | Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot. | |||
| CVE-2003-1409 | 0.03 | — | 0.03 | Dec 31, 2003 | TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message. | |||
| CVE-2003-1410 | 0.03 | — | 0.02 | Dec 31, 2003 | PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter. | |||
| CVE-2003-1411 | 0.03 | — | 0.02 | Dec 31, 2003 | PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter. | |||
| CVE-2003-1412 | 0.03 | — | 0.03 | Dec 31, 2003 | PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4)… | |||
| CVE-2003-1413 | 0.00 | — | 0.01 | Dec 31, 2003 | parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages. | |||
| CVE-2003-1414 | 0.03 | — | 0.04 | Dec 31, 2003 | Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter. | |||
| CVE-2003-1415 | 0.00 | — | 0.01 | Dec 31, 2003 | NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification. | |||
| CVE-2003-1416 | 0.00 | — | 0.01 | Dec 31, 2003 | BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command. | |||
| CVE-2003-1417 | 0.00 | — | 0.00 | Dec 31, 2003 | nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files. | |||
| CVE-2003-1418 | 0.00 | — | 0.07 | Dec 31, 2003 | Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID). | |||
| CVE-2003-1419 | 0.03 | — | 0.02 | Dec 31, 2003 | Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function. | |||
| CVE-2003-1420 | 0.00 | — | 0.02 | Dec 31, 2003 | Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header. | |||
| CVE-2003-1421 | 0.00 | — | 0.01 | Dec 31, 2003 | Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors. | |||
| CVE-2003-1422 | 0.00 | — | 0.01 | Dec 31, 2003 | Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors. | |||
| CVE-2003-1423 | 0.00 | — | 0.01 | Dec 31, 2003 | Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords. | |||
| CVE-2003-1424 | 0.00 | — | 0.01 | Dec 31, 2003 | message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie. | |||
| CVE-2003-1425 | 0.04 | — | 0.11 | Dec 31, 2003 | guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. | |||
| CVE-2003-1426 | 0.00 | — | 0.00 | Dec 31, 2003 | Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious… | |||
| CVE-2003-1427 | 0.03 | — | 0.03 | Dec 31, 2003 | Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter. | |||
| CVE-2003-1428 | 0.00 | — | 0.01 | Dec 31, 2003 | Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos. | |||
| CVE-2003-1429 | 0.00 | — | 0.03 | Dec 31, 2003 | Buffer overflow in Proxomitron Naoko 4.4 allows remote attackers to execute arbitrary code via a long request. | |||
| CVE-2003-1430 | 0.03 | — | 0.03 | Dec 31, 2003 | Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL. | |||
| CVE-2003-1431 | 0.03 | — | 0.05 | Dec 31, 2003 | Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL. | |||
| CVE-2003-1432 | 0.01 | — | 0.08 | Dec 31, 2003 | Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2)… | |||
| CVE-2003-1433 | 0.00 | — | 0.01 | Dec 31, 2003 | Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times. | |||
| CVE-2003-1434 | 0.00 | — | 0.01 | Dec 31, 2003 | login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or… | |||
| CVE-2003-1435 | 0.03 | — | 0.02 | Dec 31, 2003 | SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module. | |||
| CVE-2003-1436 | 0.03 | — | 0.02 | Dec 31, 2003 | PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter. | |||
| CVE-2003-1437 | 0.00 | — | 0.00 | Dec 31, 2003 | BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access. | |||
| CVE-2003-1438 | 0.00 | — | 0.01 | Dec 31, 2003 | Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another… | |||
| CVE-2003-1439 | 0.00 | — | 0.01 | Dec 31, 2003 | Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information. |
- CVE-2003-1390Dec 31, 2003risk 0.00cvss —epss 0.01
RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the passphrase.
- CVE-2003-1391Dec 31, 2003risk 0.00cvss —epss 0.01
RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers to guess the passphrase.
- CVE-2003-1392Dec 31, 2003risk 0.00cvss —epss 0.01
CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data.
- CVE-2003-1393Dec 31, 2003risk 0.00cvss —epss 0.03
Buffer overflow in Gupta SQLBase 8.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long EXECUTE command.
- CVE-2003-1394Dec 31, 2003risk 0.00cvss —epss 0.01
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
- CVE-2003-1395Dec 31, 2003risk 0.00cvss —epss 0.04
Buffer overflow in KaZaA Media Desktop 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a response to the ad server.
- CVE-2003-1396Dec 31, 2003risk 0.04cvss —epss 0.09
Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a filename with a long extension.
- CVE-2003-1397Dec 31, 2003risk 0.03cvss —epss 0.06
The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP request containing a long string that gets passed to the ShowDocument method.
- CVE-2003-1398Dec 31, 2003risk 0.00cvss —epss 0.02
Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).
- CVE-2003-1399Dec 31, 2003risk 0.00cvss —epss 0.00
eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.
- CVE-2003-1400Dec 31, 2003risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.
- CVE-2003-1401Dec 31, 2003risk 0.03cvss —epss 0.02
login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.
- CVE-2003-1402Dec 31, 2003risk 0.00cvss —epss 0.02
PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.
- CVE-2003-1403Dec 31, 2003risk 0.00cvss —epss 0.01
foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.
- CVE-2003-1404Dec 31, 2003risk 0.00cvss —epss 0.01
DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.
- CVE-2003-1405Dec 31, 2003risk 0.03cvss —epss 0.04
DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.
- CVE-2003-1406Dec 31, 2003risk 0.03cvss —epss 0.03
PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.
- CVE-2003-1407Dec 31, 2003risk 0.03cvss —epss 0.03
Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.
- CVE-2003-1408Dec 31, 2003risk 0.00cvss —epss 0.01
Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.
- CVE-2003-1409Dec 31, 2003risk 0.03cvss —epss 0.03
TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter to (1) in.php or (2) out.php, which reveals the path to the TOPo directory in the error message.
- CVE-2003-1410Dec 31, 2003risk 0.03cvss —epss 0.02
PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary PHP code via the cer_skin parameter.
- CVE-2003-1411Dec 31, 2003risk 0.03cvss —epss 0.02
PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arbitrary PHP code via the emailreader_ini parameter.
- CVE-2003-1412Dec 31, 2003risk 0.03cvss —epss 0.03
PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4)…
- CVE-2003-1413Dec 31, 2003risk 0.00cvss —epss 0.01
parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.
- CVE-2003-1414Dec 31, 2003risk 0.03cvss —epss 0.04
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.
- CVE-2003-1415Dec 31, 2003risk 0.00cvss —epss 0.01
NetCharts XBRL Server 4.0.0 allows remote attackers to obtain sensitive information via an HTTP request with an invalid chunked transfer encoding specification.
- CVE-2003-1416Dec 31, 2003risk 0.00cvss —epss 0.01
BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.
- CVE-2003-1417Dec 31, 2003risk 0.00cvss —epss 0.00
nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files.
- CVE-2003-1418Dec 31, 2003risk 0.00cvss —epss 0.07
Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).
- CVE-2003-1419Dec 31, 2003risk 0.03cvss —epss 0.02
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
- CVE-2003-1420Dec 31, 2003risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Opera 6.0 through 7.0 with automatic redirection disabled allows remote attackers to inject arbitrary web script or HTML via the HTTP Location header.
- CVE-2003-1421Dec 31, 2003risk 0.00cvss —epss 0.01
Unspecified vulnerability in mod_mysql_logger shared object in SuckBot 0.006 allows remote attackers to cause a denial of service (seg fault) via unknown attack vectors.
- CVE-2003-1422Dec 31, 2003risk 0.00cvss —epss 0.01
Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.
- CVE-2003-1423Dec 31, 2003risk 0.00cvss —epss 0.01
Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.
- CVE-2003-1424Dec 31, 2003risk 0.00cvss —epss 0.01
message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.
- CVE-2003-1425Dec 31, 2003risk 0.04cvss —epss 0.11
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
- CVE-2003-1426Dec 31, 2003risk 0.00cvss —epss 0.00
Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious…
- CVE-2003-1427Dec 31, 2003risk 0.03cvss —epss 0.03
Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to read arbitrary files, such as the netgear.cfg configuration file, via a hex-encoded (%2e%2e%2f) ../ (dot dot slash) in the port parameter.
- CVE-2003-1428Dec 31, 2003risk 0.00cvss —epss 0.01
Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.
- CVE-2003-1429Dec 31, 2003risk 0.00cvss —epss 0.03
Buffer overflow in Proxomitron Naoko 4.4 allows remote attackers to execute arbitrary code via a long request.
- CVE-2003-1430Dec 31, 2003risk 0.03cvss —epss 0.03
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.
- CVE-2003-1431Dec 31, 2003risk 0.03cvss —epss 0.05
Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.
- CVE-2003-1432Dec 31, 2003risk 0.01cvss —epss 0.08
Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2)…
- CVE-2003-1433Dec 31, 2003risk 0.00cvss —epss 0.01
Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.
- CVE-2003-1434Dec 31, 2003risk 0.00cvss —epss 0.01
login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or…
- CVE-2003-1435Dec 31, 2003risk 0.03cvss —epss 0.02
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
- CVE-2003-1436Dec 31, 2003risk 0.03cvss —epss 0.02
PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.
- CVE-2003-1437Dec 31, 2003risk 0.00cvss —epss 0.00
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
- CVE-2003-1438Dec 31, 2003risk 0.00cvss —epss 0.01
Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another…
- CVE-2003-1439Dec 31, 2003risk 0.00cvss —epss 0.01
Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.