LiveActive security incident?Get immediate response
CVE archive

2003 CVE Archive

Browse CVE records published in 2003 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1504 matching CVEs · Page 12 of 31.

Unknown · CVSS Not scored

CVE-2003-1129: Buffer overflow in the Yahoo!

Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat.

Published Mar 12, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1133: Rit Research Labs The Bat!

Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read other users' email messages.

Published May 10, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1121: Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised pr...

Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary configuration via the RunAdmin services (SLRAserver.exe and SLRAclient.exe).

Published Mar 12, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1114: The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways...

The Session Initiation Protocol (SIP) implementation in Mediatrix Telecom VoIP Access Devices and Gateways running SIPv2.4 and SIPv4.3 firmware allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

Published Mar 11, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1109: The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7...

The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

Published Mar 11, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1116: The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Orac...

The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.

Published Mar 12, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1110: The Session Initiation Protocol (SIP) implementation in Columbia SIP User Agent (sipc) 1.74 and other versi...

The Session Initiation Protocol (SIP) implementation in Columbia SIP User Agent (sipc) 1.74 and other versions before sipc 2.0 build 2003-02-21 allows remote attackers to cause a denial of service or execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.

Published Mar 11, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2003-1033: The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INS...

The (1) instdbmsrv and (2) instlserver programs in SAP DB Development Tools 7.x trust the user-provided INSTROOT environment variable as a path when assigning setuid permissions to the lserver program, which allows local users to gain root privileges via a modified INSTROOT that points to a malicious dbmsrv or lserver program.

Published Mar 16, 2004 · Updated Aug 8, 2024