LiveActive security incident?Get immediate response
CVE archive

October 2003

Browse CVE records published in October 2003, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 269 matching CVEs · Page 5 of 6.

Unknown · CVSS Not scored

CVE-2003-0844: mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without th...

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.

Published Oct 9, 2003 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-0863: The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) w...

The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_mode_include_dir variable is not specified in configuration, which differs from the previous failure value and may allow remote attackers to exploit file include vulnerabilities in PHP applications.

Published Oct 15, 2003 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-0845: Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when runnin...

Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.

Published Oct 9, 2003 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-0874: Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitr...

Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.

Published Oct 25, 2003 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-0843: Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later offic...

Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header.

Published Oct 9, 2003 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-0813: A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed all...

A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.

Published Oct 15, 2003 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-0838: Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary progr...

Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).

Published Oct 7, 2003 · Updated Aug 8, 2024