CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-1421

    Last Modified: 16 Apr 2026

    SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1423

    Last Modified: 16 Apr 2026

    tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter.

    Published: 18 Mar 2003
    7.8
    High

    CVE-2002-1426

    Last Modified: 16 Apr 2026

    HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1422

    Last Modified: 16 Apr 2026

    admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1432

    Last Modified: 16 Apr 2026

    MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1433

    Last Modified: 16 Apr 2026

    Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.

    Published: 18 Mar 2003
    6.8
    Medium

    CVE-2002-1434

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1461

    Last Modified: 16 Apr 2026

    Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1462

    Last Modified: 16 Apr 2026

    details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

    Published: 18 Mar 2003
    6.8
    Medium

    CVE-2002-1464

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1465

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

    Published: 18 Mar 2003
    10
    Critical

    CVE-2002-1466

    Last Modified: 16 Apr 2026

    CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.

    Published: 18 Mar 2003
    4.6
    Medium

    CVE-2002-1473

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1474

    Last Modified: 16 Apr 2026

    Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1475

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service.

    Published: 18 Mar 2003
    6.8
    Medium

    CVE-2002-1480

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1481

    Last Modified: 16 Apr 2026

    savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.

    Published: 18 Mar 2003
    10
    Critical

    CVE-2002-1482

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1487

    Last Modified: 16 Apr 2026

    The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, (7) 218, (8) 243, (9) 302, (10) 317, (11) 324, (12) 332, (13) 333, (14) 352, and (15) 367.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1488

    Last Modified: 16 Apr 2026

    The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian user is not in.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1489

    Last Modified: 16 Apr 2026

    Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.

    Published: 18 Mar 2003
    7.2
    High

    CVE-2002-1500

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which produces file descriptors larger than FD_SETSIZE, which are not checked by FD_SET().

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1498

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SWServer 2.2 and earlier allows remote attackers to read arbitrary files via a URL containing .. sequences with "/" or "\" characters.

    Published: 18 Mar 2003
    7.2
    High

    CVE-2002-1506

    Last Modified: 16 Apr 2026

    Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1507

    Last Modified: 16 Apr 2026

    Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports 7778 or 10777.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1515

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter.

    Published: 18 Mar 2003
    4.3
    Medium

    CVE-2002-1526

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1527

    Last Modified: 16 Apr 2026

    emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message.

    Published: 18 Mar 2003
    5.8
    Medium

    CVE-2002-1533

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1535

    Last Modified: 16 Apr 2026

    Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1536

    Last Modified: 16 Apr 2026

    Molly IRC bot 0.5 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $host variable for nslookup.pl, (2) the $to, $from, or $message variables in pop.pl, (3) the $words or $text variables in sms.pl, or (4) the $server or $printer variables in hpled.pl.

    Published: 18 Mar 2003
    4.6
    Medium

    CVE-2002-1551

    Last Modified: 16 Apr 2026

    Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1553

    Last Modified: 16 Apr 2026

    Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist.

    Published: 18 Mar 2003
    4.6
    Medium

    CVE-2002-1554

    Last Modified: 16 Apr 2026

    Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1555

    Last Modified: 16 Apr 2026

    Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2003-0069

    Last Modified: 16 Apr 2026

    The PuTTY terminal emulator 0.53 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2003-0122

    Last Modified: 16 Apr 2026

    Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2003-0123

    Last Modified: 16 Apr 2026

    Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2003-0125

    Last Modified: 16 Apr 2026

    Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1410

    Last Modified: 16 Apr 2026

    Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1427

    Last Modified: 16 Apr 2026

    The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1431

    Last Modified: 16 Apr 2026

    Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host to an internal web server, which allows remote attackers to hide which host is being used to access the web server.

    Published: 18 Mar 2003
    4.6
    Medium

    CVE-2002-1439

    Last Modified: 16 Apr 2026

    Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files.

    Published: 18 Mar 2003
    10
    Critical

    CVE-2002-1440

    Last Modified: 16 Apr 2026

    The Gateway GS-400 server has a default root password of "0001n" that can not be changed via the administrative interface, which can allow attackers to gain root privileges.

    Published: 18 Mar 2003
    9.8
    Critical

    CVE-2002-1484

    Last Modified: 16 Apr 2026

    DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.

    Published: 18 Mar 2003
    4.3
    Medium

    CVE-2002-1495

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that are displayed in a pop-up window, and (3) certain malicious attributes within otherwise safe tags, such as onMouseOver.

    Published: 18 Mar 2003
    7.2
    High

    CVE-2002-1503

    Last Modified: 16 Apr 2026

    Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdcmd, (3) afd_ctrl, (4) init_afd, (5) mafd, (6) mon_ctrl, (7) show_olog, or (8) udc.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1539

    Last Modified: 16 Apr 2026

    Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.

    Published: 18 Mar 2003
    5
    Medium

    CVE-2002-1542

    Last Modified: 16 Apr 2026

    SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.

    Published: 18 Mar 2003
    7.5
    High

    CVE-2002-1546

    Last Modified: 16 Apr 2026

    BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence.

    Published: 18 Mar 2003