Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1444 Improper Input Validation vulnerability in Kaspersky LAB Kaspersky Anti-Virus 4.0.9.0
Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.
4.4
2003-12-31 CVE-2003-1443 Improper Input Validation vulnerability in Kaspersky LAB Kaspersky Anti-Virus 4.0.9.0
Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.
4.4
2003-12-31 CVE-2003-1442 Improper Authentication vulnerability in Ericsson Hm220Dp Adsl Modem
The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.
network
low complexity
ericsson CWE-287
7.5
2003-12-31 CVE-2003-1441 Improper Input Validation vulnerability in Posadis
Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.
network
posadis CWE-20
4.3
2003-12-31 CVE-2003-1440 Improper Input Validation vulnerability in Burton Computer Corporation Spamprobe 0.8A
SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.
4.3
2003-12-31 CVE-2003-1439 Credentials Management vulnerability in Silc Secure Internet Live Conferencing 0.9.11/0.9.12
Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.
network
silc CWE-255
4.3
2003-12-31 CVE-2003-1438 Race Condition vulnerability in BEA Weblogic Server
Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.
network
bea CWE-362
4.3
2003-12-31 CVE-2003-1437 Unspecified vulnerability in BEA Weblogic Server 7.0/7.0.0.1
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
local
low complexity
hp ibm microsoft redhat sun bea
2.1
2003-12-31 CVE-2003-1436 Code Injection vulnerability in Crossnuke Nukebrowser
PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.
network
crossnuke CWE-94
6.8
2003-12-31 CVE-2003-1435 SQL Injection vulnerability in Francisco Burzi PHP-Nuke 5.6/6.0
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
network
low complexity
francisco-burzi CWE-89
7.5