CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-2385

    Last Modified: 16 Apr 2026

    Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL containing a long voice phone number.

    Published: 31 Dec 2002
    7.1
    High

    CVE-2002-2355

    Last Modified: 16 Apr 2026

    Netgear FM114P firmware 1.3 wireless firewall, when configured to backup configuration information, stores DDNS (DynDNS) user name and password, MAC address filtering table and possibly other information in cleartext, which could allow local users to obtain sensitive information.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2354

    Last Modified: 16 Apr 2026

    Netgear FM114P firmware 1.3 wireless firewall allows remote attackers to cause a denial of service (crash or hang) via a large number of TCP connection requests.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2353

    Last Modified: 16 Apr 2026

    tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.

    Published: 31 Dec 2002
    5.8
    Medium

    CVE-2002-2352

    Last Modified: 16 Apr 2026

    The NBActiveX.ocx ActiveX control in NeoBook 4 allows remote attackers to install and execute arbitrary programs.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2351

    Last Modified: 16 Apr 2026

    Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2350

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in z_user_show.php in dbtreelistproperty_method.php in Zorum 2.4 allows remote attackers to inject arbitrary web script or HTML via the class parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2349

    Last Modified: 16 Apr 2026

    phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.

    Published: 31 Dec 2002
    7.1
    High

    CVE-2002-2328

    Last Modified: 16 Apr 2026

    Active Directory in Windows 2000, when supporting Kerberos V authentication and GSSAPI, allows remote attackers to cause a denial of service (hang) via an LDAP client that sets the page length to zero during a large request.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2323

    Last Modified: 16 Apr 2026

    Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2322

    Last Modified: 16 Apr 2026

    Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2321

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2320

    Last Modified: 16 Apr 2026

    MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1872

    Last Modified: 16 Apr 2026

    Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1884

    Last Modified: 16 Apr 2026

    index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin".

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1885

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1886

    Last Modified: 16 Apr 2026

    TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1887

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1888

    Last Modified: 16 Apr 2026

    CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1889

    Last Modified: 16 Apr 2026

    Off-by-one buffer overflow in the context_action function in context.c of Logsurfer 1.41 through 1.5a allows remote attackers to cause a denial of service (crash) via a malformed log entry.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1897

    Last Modified: 16 Apr 2026

    MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, possibly triggering a buffer overflow.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1898

    Last Modified: 16 Apr 2026

    Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is executed by Terminal.app window.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1899

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in IceWarp Web Mail 3.3.3 and 3.4.5 allows remote attackers to inject arbitrary web script or HTML via the "Full Name" (addressname) parameter.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1900

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1901

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bodo Bauer BBGallery 1.0 allows remote attackers to inject arbitrary web script or HTML via image tags.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1902

    Last Modified: 16 Apr 2026

    CGIForum 1.0 through 1.05 allows remote attackers to cause a denial of service (infinite recursion) by creating a message board post that is a child of an outdated parent.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1910

    Last Modified: 16 Apr 2026

    Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1919

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password fields.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1920

    Last Modified: 16 Apr 2026

    Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1921

    Last Modified: 16 Apr 2026

    The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1922

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1923

    Last Modified: 16 Apr 2026

    The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1924

    Last Modified: 16 Apr 2026

    PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackers to modify or create files in that directory.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1925

    Last Modified: 16 Apr 2026

    Tiny Personal Firewall 3.0 through 3.0.6 allows remote attackers to cause a denial of service (crash) by via SYN, UDP, ICMP and TCP portscans when the administrator selects the Log tab of the Personal Firewall Agent module.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1931

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1940

    Last Modified: 16 Apr 2026

    LCC-Win32 3.2 compiler, when running on Windows 95, 98, or ME, writes portions of previously used memory after the import table, which could allow attackers to gain sensitive information. NOTE: it has been reported that this problem is due to the OS and not the application.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1958

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1960

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Cybozu Share360 1.1 allows remote attackers to inject arbitrary web script or HTML via an HTML link.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1961

    Last Modified: 16 Apr 2026

    Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL whose hostname portion uses a fully qualified domain name (FQDN) that ends in a "." (dot).

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1984

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1993

    Last Modified: 16 Apr 2026

    webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1994

    Last Modified: 16 Apr 2026

    advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1995

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn parameter.

    Published: 31 Dec 2002
    2.6
    Low

    CVE-2002-1996

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1997

    Last Modified: 16 Apr 2026

    ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2016

    Last Modified: 16 Apr 2026

    User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2018

    Last Modified: 16 Apr 2026

    sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2019

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary PHP code via the include_file parameter.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2020

    Last Modified: 16 Apr 2026

    Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26 uses a default administrator password and accepts admin logins on the external interface, which allows remote attackers to gain privileges if the password is not changed.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2021

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 31 Dec 2002