Vulnerabilities > Linux > Linux Kernel

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1423 Permissions, Privileges, and Access Controls vulnerability in Petitforum
Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords.
network
low complexity
linux microsoft unix petitforum CWE-264
5.0
2003-12-31 CVE-2003-1372 Cross-Site Scripting vulnerability in Myphpnuke 1.8.8
Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters.
4.3
2003-12-31 CVE-2003-1332 Remote Security vulnerability in Samba
Stack-based buffer overflow in the reply_nttrans function in Samba 2.2.7a and earlier allows remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2003-0201.
network
low complexity
linux samba
7.5
2003-12-31 CVE-2003-1327 Remote Stack-based Buffer Overrun vulnerability in Wu-Ftpd SockPrintf()
Buffer overflow in the SockPrintf function in wu-ftpd 2.6.2 and earlier, when compiled with MAIL_ADMIN option enabled on a system that supports very long pathnames, might allow remote anonymous users to execute arbitrary code by uploading a file with a long pathname, which triggers the overflow when wu-ftpd constructs a notification message to the administrator.
network
linux washington-university
critical
9.3
2003-12-31 CVE-2003-1161 Unspecified vulnerability in Linux Kernel 2.6Test9Cvs
exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function.
local
low complexity
linux
7.2
2003-12-15 CVE-2003-0961 Unspecified vulnerability in Linux Kernel
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to gain root privileges.
local
low complexity
linux
7.2
2003-08-27 CVE-2003-0619 Unspecified vulnerability in Linux Kernel
Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.
network
low complexity
linux
5.0
2003-08-27 CVE-2003-0467 Unspecified vulnerability in Linux Kernel 2.4.20/2.4.21
Unknown vulnerability in ip_nat_sack_adjust of Netfilter in Linux kernels 2.4.20, and some 2.5.x, when CONFIG_IP_NF_NAT_FTP or CONFIG_IP_NF_NAT_IRC is enabled, or the ip_nat_ftp or ip_nat_irc modules are loaded, allows remote attackers to cause a denial of service (crash) in systems using NAT, possibly due to an integer signedness error.
network
low complexity
linux
5.0
2003-08-27 CVE-2003-0462 A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).
local
high complexity
mandrakesoft linux
1.2
2003-08-27 CVE-2003-0187 Unspecified vulnerability in Linux Kernel 2.4.20
The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.
network
low complexity
linux
5.0