Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1445 Buffer Errors vulnerability in Rarlab FAR Manager 1.65/1.70Beta1/1.70Beta4
Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.
local
low complexity
rarlab CWE-119
4.6
2003-12-31 CVE-2003-1444 Improper Input Validation vulnerability in Kaspersky LAB Kaspersky Anti-Virus 4.0.9.0
Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname.
4.4
2003-12-31 CVE-2003-1443 Improper Input Validation vulnerability in Kaspersky LAB Kaspersky Anti-Virus 4.0.9.0
Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com.
4.4
2003-12-31 CVE-2003-1441 Improper Input Validation vulnerability in Posadis
Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.
network
posadis CWE-20
4.3
2003-12-31 CVE-2003-1440 Improper Input Validation vulnerability in Burton Computer Corporation Spamprobe 0.8A
SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.
4.3
2003-12-31 CVE-2003-1439 Credentials Management vulnerability in Silc Secure Internet Live Conferencing 0.9.11/0.9.12
Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information.
network
silc CWE-255
4.3
2003-12-31 CVE-2003-1438 Race Condition vulnerability in BEA Weblogic Server
Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.
network
bea CWE-362
4.3
2003-12-31 CVE-2003-1436 Code Injection vulnerability in Crossnuke Nukebrowser
PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter.
network
crossnuke CWE-94
6.8
2003-12-31 CVE-2003-1434 Improper Authentication vulnerability in Pete Werner Login Ldap 3.1/3.2
login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password.
6.8
2003-12-31 CVE-2003-1433 Improper Authentication vulnerability in Epic Games Unreal Engine 226F/433/436
Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.
4.3