CVE Database - 2003

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

116
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2003-0712

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the HTML encoding for the Compose New Message form in Microsoft Exchange Server 5.5 Outlook Web Access (OWA) allows remote attackers to execute arbitrary web script.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-0714

HIGH
7.50 CVSS 2.0

The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2003-0845

HIGH
7.50 CVSS 2.0

Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.

SQL Injection
WAF: High

CVE-2003-1151

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrary web script or HTML via the URL, which is displayed on a "404 Not Found" error page.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-0791

CRITICAL
9.80 CVSS 3.1

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

Insecure Deserialization
WAF: Medium

CVE-2003-0801

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Nokia Electronic Documentation (NED) 5.0 allows remote attackers to execute arbitrary web script and steal cookies via a URL to the docs/ directory that contains the script.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-0567

HIGH
7.80 CVSS 2.0

Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.

Improper Input Validation
WAF: Medium

CVE-2003-0498

HIGH
7.20 CVSS 2.0

Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.

Code Injection
WAF: Medium

CVE-2003-0367

LOW
2.10 CVSS 2.0

znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Improper Input Validation
WAF: Medium

CVE-2003-0395

HIGH
7.50 CVSS 2.0

Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.

Code Injection
WAF: Medium

CVE-2003-0286

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.

SQL Injection
WAF: High

CVE-2003-0310

MEDIUM
6.80 CVSS 2.0

Cross-site scripting (XSS) vulnerability in articleview.php for eZ publish 2.2 allows remote attackers to insert arbitrary web script.

Cross-Site Scripting (XSS)
WAF: High

CVE-2003-0377

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certain variables, as demonstrated using the GroupName variable in SiteAdmin.ASP.

SQL Injection
WAF: High

CVE-2003-0216

HIGH
9.30 CVSS 2.0

Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.

Improper Authentication
WAF: Low

CVE-2002-1484

CRITICAL
9.80 CVSS 3.1

DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.

Server-Side Request Forgery (SSRF)
WAF: Medium

CVE-2003-0041

HIGH
10.00 CVSS 2.0

Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.

OS Command Injection
WAF: High
Page 3 of 3 (116 CVEs)