VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 16 hours ago
Reset
More filters (2)
Columns
Published from 2003-01-01Published to 2003-12-31
Overview 22 matches, all in RASP scope · 2 protected · 0 KEV · 6 public PoC · 0 CISA SSVC · 0 EPSS ≥ 0.5 · 0 disputed
22matches, all in RASP scope 2protected9.1% 0KEV0.0% 6public PoC27.3% 0CISA SSVC0.0% 0EPSS ≥ 0.50.0% 0disputed0.0%
Critical 0 0.0% High 9 40.9% Medium 12 54.5% Low 1 4.5% None 0 0.0% Unknown 0 0.0%
Protected by RASP 2 9.1% Rule in development 0 0.0% Mitigation candidate 5 22.7% No exploit published 4 18.2% No fix identified 11 50.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 2 9.1% not blocked 20 90.9% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 6 27.3% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 16 72.7%
split by peak 6 / month
Unknown: 0None: 0Low: 1Medium: 12High: 9Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 11No exploit published: 4Mitigation candidate: 5Rule in development: 0Protected by RASP: 2 unrecorded: 0not established: 0not blocked: 20blocked by ARMR today: 2 No public exploit: 16Forecast only: 0Proof of concept only: 0Working exploit published: 6Exploited in the wild: 0 January 2003: 1 CVE February 2003: 4 CVEs March 2003: 1 CVE April 2003: 1 CVE May 2003: 0 CVEs June 2003: 0 CVEs July 2003: 0 CVEs August 2003: 6 CVEs September 2003: 0 CVEs October 2003: 1 CVE November 2003: 2 CVEs December 2003: 6 CVEs
Jan 03Feb 03Mar 03Apr 03May 03Jun 03Jul 03Aug 03Sep 03Oct 03Nov 03Dec 03
22 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2003-1447 Low 2003-12-31 No fix identified No public exploit IBM WebSphere Advanced Server Edition 4.0.4 uses a weak encryption algorithm (XOR and base64 encoding), which allows local users to decrypt passwords when the configuration file is exported to XML.
CVE-2003-1301 Medium 2003-12-31 No fix identified No public exploit Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x before 1.5.0_06, and as used in multiple web browsers, allows remote attackers to cause a denial of service (application crash) via deeply nested object arrays, which are not properly handled by the garbage collector and trigger invalid memory accesses.
CVE-2003-1229 High 2003-12-31 No fix identified No public exploit X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.
CVE-2003-1156 Medium 2003-12-31 No fix identified No public exploit Java Runtime Environment (JRE) and Software Development Kit (SDK) 1.4.2 through 1.4.2_02 allows local users to overwrite arbitrary files via a symlink attack on (1) unpack.log, as created by the unpack program, or (2) .mailcap1 and .mime.types1, as created by the RPM program.
CVE-2003-1123 High 2003-12-31 Mitigation candidate Working exploit published Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information within trusted applets, which allows attackers to bypass the restrictions of the Java security model.
CVE-2003-1116 Medium 2003-12-31 No fix identified No public exploit The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.
CVE-2003-0896 High 2003-11-17 Mitigation candidate Working exploit published The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.1_03 and earlier allows remote attackers to bypass sandbox restrictions and execute arbitrary code via a loaded class name that contains "/" (slash) instead of "." (dot) characters, which bypasses a call to the Security Manager's checkPackageAccess method.
CVE-2003-0866 Medium 2003-11-17 Mitigation candidate Working exploit published The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
CVE-2002-1567 Medium 2003-10-06 Mitigation candidate Working exploit published Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
CVE-2003-0633 Medium 2003-08-27 No fix identified No public exploit Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without authentication, such as the GUEST user password and the application server security key.
CVE-2003-0632 High 2003-08-27 No fix identified No public exploit Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.5.8 may allow remote attackers to execute arbitrary code via a long URL.
CVE-2003-0616 High 2003-08-27 No fix identified No public exploit Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.
CVE-2003-0610 Medium 2003-08-27 Protected by RASP No public exploit Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request.
CVE-2003-0149 High 2003-08-27 No fix identified No public exploit Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.
CVE-2003-0148 High 2003-08-27 No fix identified No public exploit The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.
CVE-2002-0690 High 2003-04-11 No fix identified No public exploit Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.
CVE-2002-1533 Medium 2003-03-31 Mitigation candidate Working exploit published Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).
CVE-2003-0045 Medium 2003-02-07 No exploit published No public exploit Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.
CVE-2003-0044 Medium 2003-02-07 No exploit published No public exploit Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
CVE-2003-0043 Medium 2003-02-07 No exploit published No public exploit Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, uses trusted privileges when processing the web.xml file, which could allow remote attackers to read portions of some files through the web.xml file.
CVE-2003-0042 Medium 2003-02-07 Protected by RASP Working exploit published Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
CVE-2002-1394 High 2003-01-17 No exploit published No public exploit Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.