Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1334 Cross-Site Scripting vulnerability in KAI Blankenhorn Bitfolge Simple and Nice Index File
Cross-site scripting (XSS) vulnerability in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2003-12-31 CVE-2003-1333 Remote Security vulnerability in Cache Database
Unspecified vulnerability in the Cache' Server Page (CSP) implementation in InterSystems Cache' 4.0.3 through 5.0.5 allows remote attackers to "gain complete control" of a server.
network
low complexity
intersystems
critical
10.0
2003-12-31 CVE-2003-1332 Remote Security vulnerability in Samba
Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.
network
low complexity
linux samba
7.5
2003-12-31 CVE-2003-1331 Buffer Overrun vulnerability in MySQL libmysqlclient Library mysql_real_connect()
Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.
network
high complexity
oracle
4.0
2003-12-31 CVE-2003-1330 Unspecified vulnerability in Clearswift Limited Mailsweeper 4.3.6Sp1
Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove.
network
low complexity
microsoft clearswift-limited
5.0
2003-12-31 CVE-2003-1329 Denial-Of-Service vulnerability in Washington University Wu-Ftpd 2.6.2
ftpd.c in wu-ftpd 2.6.2, when running on "operating systems that only allow one non-connected socket bound to the same local address," does not close failed connections, which allows remote attackers to cause a denial of service.
network
low complexity
washington-university
7.8
2003-12-31 CVE-2003-1327 Remote Stack-based Buffer Overrun vulnerability in Wu-Ftpd SockPrintf()
Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs a notification message to the administrator.
network
linux washington-university
critical
9.3
2003-12-31 CVE-2003-1325 Denial-Of-Service vulnerability in Half-Life Cstrike Dedicated Server
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related issue to CVE-2006-0734.
5.2
2003-12-31 CVE-2003-1324 Local Security vulnerability in Elmme-Mailer ELM Me+ 2.4
Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.
local
low complexity
elmme-mailer
4.6
2003-12-31 CVE-2003-1323 Remote Security vulnerability in ELM Development Group ELM 2.4
Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group via unspecified vectors.
6.8