Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1364 Improper Input Validation vulnerability in Aprelium Technologies Abyss web Server 1.1.2
Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields.
network
low complexity
aprelium-technologies CWE-20
8.5
2003-12-31 CVE-2003-1363 Unspecified vulnerability in Aprelium Technologies Abyss web Server
The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection.
network
low complexity
aprelium-technologies
6.4
2003-12-31 CVE-2003-1362 Configuration vulnerability in HP Bastille B.02.00.05
Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail aliases.
network
low complexity
hp CWE-16
7.8
2003-12-31 CVE-2003-1361 Remote Code Execution vulnerability in Veritas Bare Metal Restore
Unknown vulnerability in VERITAS Bare Metal Restore (BMR) of Tivoli Storage Manager (TSM) 3.1.0 through 3.2.1 allows remote attackers to gain root privileges on the BMR Main Server.
network
low complexity
ibm veritas
critical
10.0
2003-12-31 CVE-2003-1360 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in HP Hp-Ux
Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.
local
low complexity
hp CWE-119
7.2
2003-12-31 CVE-2003-1359 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.
local
low complexity
hp avaya CWE-119
7.2
2003-12-31 CVE-2003-1358 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux
rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.
local
low complexity
hp CWE-264
7.2
2003-12-31 CVE-2003-1357 Configuration vulnerability in Replicom Proxyview
ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
network
low complexity
replicom microsoft CWE-16
critical
10.0
2003-12-31 CVE-2003-1356 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux
The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.
local
low complexity
hp CWE-264
7.2
2003-12-31 CVE-2003-1355 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Electronic Arts Battlefield 1942 1.2/1.3
Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.
network
low complexity
electronic-arts CWE-119
7.5