CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2002-2307

    Last Modified: 16 Apr 2026

    The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2308

    Last Modified: 16 Apr 2026

    Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2309

    Last Modified: 16 Apr 2026

    php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2315

    Last Modified: 16 Apr 2026

    Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2316

    Last Modified: 16 Apr 2026

    Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network information by sniffing.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2317

    Last Modified: 16 Apr 2026

    Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumption) via an unknown method.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2318

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2326

    Last Modified: 16 Apr 2026

    The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.

    Published: 31 Dec 2002
    4.9
    Medium

    CVE-2002-2327

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting volatile properties.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2329

    Last Modified: 16 Apr 2026

    ICQ client 2001b, 2002a and 2002b allows remote attackers to cause a denial of service (CPU consumption or crash) via a message with a large number of emoticons.

    Published: 31 Dec 2002
    3.6
    Low

    CVE-2002-2334

    Last Modified: 16 Apr 2026

    Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2335

    Last Modified: 16 Apr 2026

    Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2336

    Last Modified: 16 Apr 2026

    Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2337

    Last Modified: 16 Apr 2026

    Kaspersky Anti-Hacker 1.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2348

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2333

    Last Modified: 16 Apr 2026

    Buffer overflow in konqueror in KDE 2.1 through 3.0 and 3.0.2 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attributes.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2343

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email messages.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2344

    Last Modified: 16 Apr 2026

    Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2345

    Last Modified: 16 Apr 2026

    Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2346

    Last Modified: 16 Apr 2026

    phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2358

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2359

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.

    Published: 31 Dec 2002
    9.3
    Critical

    CVE-2002-2360

    Last Modified: 16 Apr 2026

    The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.

    Published: 31 Dec 2002
    5.8
    Medium

    CVE-2002-2361

    Last Modified: 16 Apr 2026

    The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2362

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2368

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long username to (1) the GetString function in proxy.c for the SOCKS5 module or (2) the HandleS4Connection function in proxy.c for the SOCKS4 module.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2370

    Last Modified: 16 Apr 2026

    SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2371

    Last Modified: 16 Apr 2026

    Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2372

    Last Modified: 16 Apr 2026

    The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2373

    Last Modified: 16 Apr 2026

    The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2374

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2379

    Last Modified: 16 Apr 2026

    Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service (crash) via a port scan, possibly due to an ssh bug. NOTE: this issue could not be reproduced by the vendor

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2380

    Last Modified: 16 Apr 2026

    NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2381

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in (1) tetrinet_inmessage, (2) speclist_add and (3) config-getthemeinfo of GTetrinet 0.4.3 and earlier allow remote attackers to casue a denial of service and possibly execute arbitrary code.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2382

    Last Modified: 16 Apr 2026

    cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2383

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2378

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2391

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2392

    Last Modified: 16 Apr 2026

    Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2393

    Last Modified: 16 Apr 2026

    Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2394

    Last Modified: 16 Apr 2026

    InterScan VirusWall 3.6 for Linux and 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 chunked transfer encoding.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2395

    Last Modified: 16 Apr 2026

    InterScan VirusWall 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 gzip content encoding.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2404

    Last Modified: 16 Apr 2026

    Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110).

    Published: 31 Dec 2002
    4.9
    Medium

    CVE-2002-2405

    Last Modified: 16 Apr 2026

    Check Point FireWall-1 4.1 and Next Generation (NG), with UserAuth configured to proxy HTTP traffic only, allows remote attackers to pass unauthorized HTTPS, FTP and possibly other traffic through the firewall.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2406

    Last Modified: 16 Apr 2026

    Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2408

    Last Modified: 16 Apr 2026

    Gordano Messaging Server (GMS) Mail 8 (a.k.a. NTMail) only filters email messages for the first recipient, which allows remote attackers to bypass JUCE filters by sending a message to more than one user on the GMS server.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2413

    Last Modified: 16 Apr 2026

    WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name.

    Published: 31 Dec 2002
    6.8
    Medium

    CVE-2002-2415

    Last Modified: 16 Apr 2026

    Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2416

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2424

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag.

    Published: 31 Dec 2002