CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2002-2017

    Last Modified: 16 Apr 2026

    sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2032

    Last Modified: 16 Apr 2026

    sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2033

    Last Modified: 16 Apr 2026

    faqmanager.cgi in FAQManager 2.2.5 and earlier allows remote attackers to read arbitrary files by specifying the filename in the toc parameter with a trailing null character (%00).

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2034

    Last Modified: 16 Apr 2026

    The Email Sanitizer before 1.133 for Procmail allows remote attackers to bypass the mail filter and execute arbitrary code via crafted recursive multipart MIME attachments.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2035

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in RealityScape MyLogin 2000 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password in the login form.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2036

    Last Modified: 16 Apr 2026

    Sun Ray Server Software (SRSS) 1.3, when Non-Smartcard Mobility (NSCM) is enabled, allows remote attackers to login as another user by running dtlogin from a system that supports the XDMCP client.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2056

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in TeeKai Forum 1.2 allows remote attackers to inject arbitrary web script or HTML via the valid_username_online cookie.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2057

    Last Modified: 16 Apr 2026

    TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2061

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2065

    Last Modified: 16 Apr 2026

    WebCalendar 0.9.34 and earlier with 'browsing in includes directory' enabled allows remote attackers to read arbitrary include files with .inc extensions from the web root.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2066

    Last Modified: 16 Apr 2026

    BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2074

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Mailidx before 20020105 allows remote attackers to execute arbitrary SQL commands via the search web page.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2076

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Lil' HTTP server 2.1 and 2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2101

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2102

    Last Modified: 16 Apr 2026

    InfBlocks.java in JCraft JZlib before 0.0.7 allow remote attackers to cause a denial of service (NullPointerException) via an invalid block of deflated data.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2103

    Last Modified: 16 Apr 2026

    Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2104

    Last Modified: 16 Apr 2026

    graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2105

    Last Modified: 16 Apr 2026

    Microsoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2106

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2118

    Last Modified: 16 Apr 2026

    Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL.

    Published: 31 Dec 2002
    9.8
    Critical

    CVE-2002-2119

    Last Modified: 16 Apr 2026

    Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-2120

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in QNX RTOS 4.25 may allow attackers to execute arbitrary code via long filename arguments to (1) Watcom or (2) int10.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2121

    Last Modified: 16 Apr 2026

    SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a buffer overflow.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2122

    Last Modified: 16 Apr 2026

    Pointsec before 1.2 for PalmOS stores a user's PIN number in memory in plaintext, which allows a local attacker who steals an unlocked Palm to retrieve the PIN by dumping memory.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2123

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the GALLERY_BASEDIR parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2124

    Last Modified: 16 Apr 2026

    The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closing the connection while recv is executing.

    Published: 31 Dec 2002
    Unknown

    CVE-2002-2147

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1828. Reason: This candidate is a duplicate of CVE-2002-1828. Notes: All CVE users should reference CVE-2002-1828 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2146

    Last Modified: 16 Apr 2026

    cgitest.exe in Savant Web Server 3.1 and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2159

    Last Modified: 16 Apr 2026

    Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the "Block WAN" and "Remote Admin" options are disabled, which allows remote attackers to gain access.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2168

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2174

    Last Modified: 16 Apr 2026

    The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) via a large number of connections.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2179

    Last Modified: 16 Apr 2026

    The dynamic initialization feature of the ClearPath MCP environment allows remote attackers to cause a denial of service (crash) via a TCP port scan using a tool such as nmap.

    Published: 31 Dec 2002
    6.8
    Medium

    CVE-2002-2180

    Last Modified: 16 Apr 2026

    The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via an integer signedness error.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2181

    Last Modified: 16 Apr 2026

    SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2184

    Last Modified: 16 Apr 2026

    Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2201

    Last Modified: 16 Apr 2026

    The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the printer name.

    Published: 31 Dec 2002
    3.8
    Low

    CVE-2002-2202

    Last Modified: 16 Apr 2026

    Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.

    Published: 31 Dec 2002
    4.9
    Medium

    CVE-2002-2203

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the System Serial Console terminal in Solaris 2.5.1, 2.6, and 7 allows local users to monitor keystrokes and possibly steal sensitive information.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2204

    Last Modified: 16 Apr 2026

    The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.

    Published: 31 Dec 2002
    6.2
    Medium

    CVE-2002-2210

    Last Modified: 16 Apr 2026

    The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2310

    Last Modified: 16 Apr 2026

    ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.

    Published: 31 Dec 2002
    6.2
    Medium

    CVE-2002-2221

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2230

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via a private message with a javascript: URL in the IMG tag, in which the URL ends in a ".gif" or ".jpg" string, a variant of CVE-2002-0328.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2248

    Last Modified: 16 Apr 2026

    Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2257

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the parse_field function in cgi_lib.c for LIBCGI 1.0.2 and 1.0.3 allows remote attackers to execute arbitrary code via a long argument.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2258

    Last Modified: 16 Apr 2026

    Moby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large integer or (2) non-numeric value in the Content-Length header, which causes an access violation after a failed atoi function call.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2266

    Last Modified: 16 Apr 2026

    NetScreen ScreenOS 2.8 through 4.0, when forwarding H.323 or Netmeeting traffic, allows remote attackers to cause a denial of service (firewall session table consumption) by establishing multiple half-open H.323 sessions, which are not cleaned up on garbage removal and do not time out for 36 hours.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2275

    Last Modified: 16 Apr 2026

    Fortres 101 4.1 allows local users to bypass Fortres by pressing the Windows and "F" key together for 30 seconds, which opens multiple windows and eventually causes explorer.exe to crash, which then opens an unrestricted explorer.exe.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2289

    Last Modified: 16 Apr 2026

    soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2290

    Last Modified: 16 Apr 2026

    Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.

    Published: 31 Dec 2002