Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2003-11-03 CVE-2003-1185 SQL Injection vulnerability in ThWboard
Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.
network
low complexity
thwboard
7.5
2003-11-03 CVE-2003-0901 Buffer Overflow vulnerability in PostgreSQL To_Ascii()
Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.
network
low complexity
postgresql
7.5
2003-11-03 CVE-2003-0881 Remote Security vulnerability in Mac OS X
Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.
network
low complexity
apple
7.5
2003-11-03 CVE-2003-0871 Apple Quicktime Java vulnerability in Apple Mac OS X 10.3
Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."
network
low complexity
apple
7.5
2003-11-03 CVE-2003-0855 Unspecified vulnerability in Charles Kerr PAN
Pan 0.13.3 and earlier allows remote attackers to cause a denial of service (crash) via a news post with a long author email address.
network
low complexity
charles-kerr
7.8
2003-11-03 CVE-2003-0683 Unspecified vulnerability in SGI Irix 6.5.21F/6.5.21M
NFS in SGI 6.5.21m and 6.5.21f does not perform access checks in certain configurations when an /etc/exports entry uses wildcards without any hostnames or groups, which could allow attackers to bypass intended restrictions.
network
low complexity
sgi
7.5
2003-11-03 CVE-2002-1570 Remote Heap Overflow vulnerability in Net-SNMP snmpnetstat
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variable data past the end of an array.
network
low complexity
ucd-snmp
7.5
2003-10-30 CVE-2003-1143 Remote Denial of Service vulnerability in Serious Sam Engine
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05 allow remote attackers to cause a denial of service (crash or freeze) via a TCP packet with an invalid first parameter.
network
low complexity
croteam
7.5
2003-10-29 CVE-2003-1186 Remote Buffer Overflow vulnerability in Telcondex Simplewebserver 2.12.30210Build3285
Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.
network
low complexity
telcondex
7.5
2003-10-27 CVE-2003-1150 Buffer Overrun vulnerability in Novell PMAP.NLM
Buffer overflow in the portmapper service (PMAP.NLM) in Novell NetWare 6 SP3 and ZenWorks for Desktops 3.2 SP2 through 4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown attack vectors.
network
low complexity
novell
7.5