CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2002-2425

    Last Modified: 16 Apr 2026

    Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1890

    Last Modified: 16 Apr 2026

    rhmask 1.0-9 in Red Hat Linux 7.1 allows local users to overwrite arbitrary files via a symlink attack on the mask file.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1891

    Last Modified: 16 Apr 2026

    Buffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1626

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1736

    Last Modified: 16 Apr 2026

    Unknown vulnerability in CGINews before 1.06 allow remote attackers to read arbitrary files via "unfiltered user input."

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1651

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1661

    Last Modified: 16 Apr 2026

    The leafnode server in leafnode 1.9.20 to 1.9.29 allows remote attackers to cause a denial of service (infinite loop) when leafnode requests a cross-posted article to one group whose name is a prefix of another group.

    Published: 31 Dec 2002
    6.8
    Medium

    CVE-2002-1662

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.11 allow remote attackers to execute arbitrary script on other clients via (1) search.php and (2) the "Your name" field during account registration.

    Published: 31 Dec 2002
    1.2
    Low

    CVE-2002-1674

    Last Modified: 16 Apr 2026

    procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2288

    Last Modified: 16 Apr 2026

    Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.

    Published: 31 Dec 2002
    6.6
    Medium

    CVE-2002-2263

    Last Modified: 16 Apr 2026

    The installation program for HP-UX Visualize Conference B.11.00.11 running on HP-UX 11.00 and 11.11 installs /etc/dt and its subdirecties with insecure permissions, which allows local users to read or write arbitrary files.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2262

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2261

    Last Modified: 16 Apr 2026

    Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2250

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter to the xp_freedll extended stored procedure or (2) a long database name argument to the DBCC CHECKVERIFY function.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2256

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in pWins Webserver 0.2.5 and earlier allows remote attackers to read arbitrary files via Unicode characters.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2255

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2254

    Last Modified: 16 Apr 2026

    The experimental IP packet queuing feature in Netfilter / IPTables in Linux kernel 2.4 up to 2.4.19 and 2.5 up to 2.5.31, when a privileged process exits and network traffic is not being queued, may allow a later process with the same Process ID (PID) to access certain network traffic that would otherwise be restricted.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2253

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header name, (2) a long IMAP flag, or (3) a script that generates a large number of errors that overflow the resulting error string.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2242

    Last Modified: 16 Apr 2026

    The Apple Package Manager in KisMAC 0.02a and earlier modifies file permissions of sensitive files after installation, which could allow attackers to conduct unauthorized activities on those files.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2243

    Last Modified: 16 Apr 2026

    Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2245

    Last Modified: 16 Apr 2026

    ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2247

    Last Modified: 16 Apr 2026

    The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2241

    Last Modified: 16 Apr 2026

    Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2251

    Last Modified: 16 Apr 2026

    Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a long argument.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2252

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2234

    Last Modified: 16 Apr 2026

    NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests.

    Published: 31 Dec 2002
    8.5
    High

    CVE-2002-2232

    Last Modified: 16 Apr 2026

    Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2238

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2237

    Last Modified: 16 Apr 2026

    tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2236

    Last Modified: 16 Apr 2026

    Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2235

    Last Modified: 16 Apr 2026

    member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.

    Published: 31 Dec 2002
    5.1
    Medium

    CVE-2002-2223

    Last Modified: 16 Apr 2026

    Buffer overflow in NetScreen-Remote 8.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) large number of payloads, or (3) a long payload.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2229

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2228

    Last Modified: 16 Apr 2026

    MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2227

    Last Modified: 16 Apr 2026

    Buffer underflow in ssldump 0.9b2 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted SSLv2 challenge value.

    Published: 31 Dec 2002
    5.1
    Medium

    CVE-2002-2225

    Last Modified: 16 Apr 2026

    SafeNet VPN client allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly involving buffer overflows using (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload.

    Published: 31 Dec 2002
    5.1
    Medium

    CVE-2002-2224

    Last Modified: 16 Apr 2026

    Buffer overflow in PGPFreeware 7.03 running on Windows NT 4.0 SP6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) large number of payloads, or (3) a long payload.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1969

    Last Modified: 16 Apr 2026

    Magic Notebook 1.0b and 1.1b allows remote attackers to cause a denial of service (crash) via an invalid username during login.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1970

    Last Modified: 16 Apr 2026

    SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1971

    Last Modified: 16 Apr 2026

    The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1972

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Parallel port powerSwitch (aka pp_powerSwitch) 0.1 does not properly enforce access controls, which allows local users to access arbitrary ports.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1983

    Last Modified: 16 Apr 2026

    The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1967

    Last Modified: 16 Apr 2026

    Buffer overflow in XiRCON 1.0 Beta 4 allows remote attackers to cause a denial of service (disconnect) via a long (1) ctcp, (2) primsg, (3) msg, or (4) notice command.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1978

    Last Modified: 16 Apr 2026

    IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1981

    Last Modified: 16 Apr 2026

    Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1982

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1976

    Last Modified: 16 Apr 2026

    ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1977

    Last Modified: 16 Apr 2026

    Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1987

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1988

    Last Modified: 16 Apr 2026

    Resin 2.1.1 allows remote attackers to cause a denial of service (memory consumption and hang) via a URL with long variables for non-existent resources.

    Published: 31 Dec 2002