CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2002-1990

    Last Modified: 16 Apr 2026

    Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1991

    Last Modified: 16 Apr 2026

    PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1992

    Last Modified: 16 Apr 2026

    Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2002

    Last Modified: 16 Apr 2026

    Buffer overflow in libc in Compaq Tru64 4.0F, 5.0, 5.1 and 5.1A allows attackers to execute arbitrary code via long (1) LANG and (2) LOCPATH environment variables.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2003

    Last Modified: 16 Apr 2026

    ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via certain network packets generated by nmap.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2004

    Last Modified: 16 Apr 2026

    portmapper in Compaq Tru64 4.0G and 5.0A allows remote attackers to cause a denial of service via a flood of packets.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2005

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2010

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2011

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2012

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2013

    Last Modified: 16 Apr 2026

    Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2014

    Last Modified: 16 Apr 2026

    Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2015

    Last Modified: 16 Apr 2026

    PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2009

    Last Modified: 16 Apr 2026

    Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2027

    Last Modified: 16 Apr 2026

    Database of Our Owlish Wisdom (DOOW) 0.1 through 0.2.1 does not properly verify user permissions, which allows remote attackers to perform unauthorized activities.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2030

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in SQLData Enterprise Server 3.0 allows remote attacker to execute arbitrary code and cause a denial of service via a long HTTP request.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2026

    Last Modified: 16 Apr 2026

    Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2040

    Last Modified: 16 Apr 2026

    The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2041

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2042

    Last Modified: 16 Apr 2026

    ptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, which could allow local users to execute arbitrary code by modifying running processes.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2043

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2044

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the phpinfo action.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2051

    Last Modified: 16 Apr 2026

    The processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a symlink attack on files specified as hostnames in a log file.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2052

    Last Modified: 16 Apr 2026

    Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cause a denial of service via port scans such as (1) scanning all ports on a single host and (2) scanning a network of hosts for a single open port through the router. NOTE: the vendor could not reproduce this issue, saying that the original reporter was using an interim release of the software.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2053

    Last Modified: 16 Apr 2026

    The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, which causes a loop.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2054

    Last Modified: 16 Apr 2026

    TeeKai Forum 1.2 allows remote attackers to authenticate as the administrator and and gain privileged web forum access by setting the valid_level cookie to admin.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2055

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2060

    Last Modified: 16 Apr 2026

    Buffer overflow in Links 2.0 pre4 allows remote attackers to crash client browsers and possibly execute arbitrary code via gamma tables in large 16-bit PNG images.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2063

    Last Modified: 16 Apr 2026

    AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2064

    Last Modified: 16 Apr 2026

    isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2069

    Last Modified: 16 Apr 2026

    PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2070

    Last Modified: 16 Apr 2026

    SecureClean 3 build 2.0 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2071

    Last Modified: 16 Apr 2026

    Compaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lockd, (5) snmp, (6) ttdbserverd, and possibly other services via a TCP SYN scan, as demonstrated using nmap.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2072

    Last Modified: 16 Apr 2026

    java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2084

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2) topic parameters.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2085

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in page.cgi of WWWeBBB Forum 3.82 beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2086

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in magicHTML of SquirrelMail before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via (1) "<<script" in unspecified input fields or (2) a javascript: URL in the src attribute of an IMG tag.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-2087

    Last Modified: 16 Apr 2026

    Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_drop, (2) gds_lock_mgr, or (3) gds_inet_server.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2088

    Last Modified: 16 Apr 2026

    The MOSIX Project clump/os 5.4 creates a default VNC account without a password, which allows remote attackers to gain root access.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2090

    Last Modified: 16 Apr 2026

    Caucho Technology Resin server 2.1.1 to 2.1.2 allows remote attackers to obtain server's root path via requests for MS-DOS device names such as lpt9.xtp.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2083

    Last Modified: 16 Apr 2026

    The Novell Netware client running on Windows 95 allows local users to bypass the login and open arbitrary files via the "What is this?" help feature, which can be launched from the Novell Netware login screen.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2095

    Last Modified: 16 Apr 2026

    Joe Testa hellbent 01 webserver allows attackers to read files that are specified in the hellbent.prefs file by creating a file with a similar name in the web root, as demonstrated using (1) index.webroot and (2) index.ipallow.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2096

    Last Modified: 16 Apr 2026

    Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary code via a long (1) username or (2) password.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2097

    Last Modified: 16 Apr 2026

    The compression code in MaraDNS before 0.9.01 allows remote attackers to cause a denial of service via crafted DNS packets.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2098

    Last Modified: 16 Apr 2026

    Buffer overflow in axspawn.c in Axspawn-pam before 0.2.1a allows remote attackers to execute arbitrary code via large packets.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2099

    Last Modified: 16 Apr 2026

    Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2100

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2094

    Last Modified: 16 Apr 2026

    Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root's parent, which generates a 403 error message if the parent is incorrect, but a normal response if the parent is correct.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2112

    Last Modified: 16 Apr 2026

    RCA Digital Cable Modem DCM225 and DCM225E, and other modems that must conform to the Data-over-Cable Service Interface Specifications DOCSIS standard, uses the "public" community string for SNMP access, which allows remote attackers to read or write MIB information.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2113

    Last Modified: 16 Apr 2026

    search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter.

    Published: 31 Dec 2002