Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1164 Cross-Site Scripting vulnerability in Mldonkey 2.5.4
Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTML via the URI, which is injected into the HTML error page.
network
mldonkey
4.3
2003-12-31 CVE-2003-1163 Remote Denial of Service vulnerability in Ganglia gmond Malformed Packet
hash.c in Ganglia gmond 2.5.3 allows remote attackers to cause a denial of service (segmentation fault) via a UDP packet that contains a single-byte name string, which is used as an out-of-bounds array index.
network
low complexity
ganglia
5.0
2003-12-31 CVE-2003-1162 Unspecified vulnerability in Tritanium Scripts Tritanium Bulletin Board
index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.
network
low complexity
tritanium-scripts
5.0
2003-12-31 CVE-2003-1161 Unspecified vulnerability in Linux Kernel 2.6Test9Cvs
exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.
local
low complexity
linux
7.2
2003-12-31 CVE-2003-1158 Buffer Overflow vulnerability in Plug and Play Software Plug and Play web Server 1.0.002C
Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands.
network
low complexity
plug-and-play-software
5.0
2003-12-31 CVE-2003-1157 Cross-Site Scripting vulnerability in Citrix Metaframe 1.0
Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.
network
citrix
4.3
2003-12-31 CVE-2003-1156 File Corruption vulnerability in SUN JDK and JRE
Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.
local
low complexity
sun
4.6
2003-12-31 CVE-2003-1155 Local Insecure File Creation Symlink vulnerability in X-CD-Roast
X-CD-Roast 0.98 alpha10 through alpha14 allows local users to overwrite arbitrary files via a symlink attack on an unknown file.
local
low complexity
x-cd-roast
4.6
2003-12-31 CVE-2003-1154 Unspecified vulnerability in Clearswift Mailsweeper
MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants.
network
low complexity
clearswift
7.5
2003-12-31 CVE-2003-1153 Unspecified vulnerability in Bytehoard 0.7/0.71
byteHoard 0.7 and 0.71 allows remote attackers to list arbitrary files and directories via a direct request to files.inc.php.
network
low complexity
bytehoard
5.0