Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2003-12-31 | CVE-2003-1446 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Rogue 5.22/985.0 Buffer overflow in the save_into_file function in save.c for Rogue 5.2-2 allows local users to execute arbitrary code with games group privileges by setting a long HOME environment variable and invoking the save game function with a ~ (tilde). | 4.9 |
2003-12-31 | CVE-2003-1445 | Buffer Errors vulnerability in Rarlab FAR Manager 1.65/1.70Beta1/1.70Beta4 Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname. | 4.6 |
2003-12-31 | CVE-2003-1444 | Improper Input Validation vulnerability in Kaspersky LAB Kaspersky Anti-Virus 4.0.9.0 Kaspersky Antivirus (KAV) 4.0.9.0 allows local users to cause a denial of service (CPU consumption or crash) and prevent malicious code from being detected via a file with a long pathname. | 4.4 |
2003-12-31 | CVE-2003-1443 | Improper Input Validation vulnerability in Kaspersky LAB Kaspersky Anti-Virus 4.0.9.0 Kaspersky Antivirus (KAV) 4.0.9.0 does not detect viruses in files with MS-DOS device names in their filenames, which allows local users to bypass virus protection, as demonstrated using aux.vbs and aux.com. | 4.4 |
2003-12-31 | CVE-2003-1441 | Improper Input Validation vulnerability in Posadis Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference. | 4.3 |
2003-12-31 | CVE-2003-1440 | Improper Input Validation vulnerability in Burton Computer Corporation Spamprobe 0.8A SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions. | 4.3 |
2003-12-31 | CVE-2003-1439 | Credentials Management vulnerability in Silc Secure Internet Live Conferencing 0.9.11/0.9.12 Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information. | 4.3 |
2003-12-31 | CVE-2003-1438 | Race Condition vulnerability in BEA Weblogic Server Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user. | 4.3 |
2003-12-31 | CVE-2003-1436 | Code Injection vulnerability in Crossnuke Nukebrowser PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the filhead parameter. | 6.8 |
2003-12-31 | CVE-2003-1434 | Improper Authentication vulnerability in Pete Werner Login Ldap 3.1/3.2 login_ldap 3.1 and 3.2 allows remote attackers to initiate unauthenticated bind requests if (1) bind_anon_dn is on, which allows a bind with no password provided, (2) bind_anon_cred is on, which allows a bind with no DN, or (3) bind_anon is on, which allows a bind with no DN or password. | 6.8 |