CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-2114

    Last Modified: 16 Apr 2026

    Artekopia Netjuke before 1.0 b7 allows remote attackers to execute arbitrary code on the web server, possibly via the section parameter, which is passed to an eval call.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2115

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Hyper NIKKI System (HNS) Lite before 0.9 and HNS before 2.10-pl2 allows remote attackers to inject arbitrary web script or HTML.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2116

    Last Modified: 16 Apr 2026

    Netgear RM-356 and RT-338 series SOHO routers allow remote attackers to cause a denial of service (crash) via a UDP port scan, as demonstrated using nmap.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-2128

    Last Modified: 16 Apr 2026

    editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. (dot dot) sequences in the file parameter.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2129

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2130

    Last Modified: 16 Apr 2026

    publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASEDIR parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2131

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Perl-HTTPd before 1.0.2 allows remote attackers to view arbitrary files via a .. (dot dot) in an unknown argument.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2132

    Last Modified: 16 Apr 2026

    Windows File Protection (WFP) in Windows 2000 and XP does not remove old security catalog .CAT files, which could allow local users to replace new files with vulnerable old files that have valid hash codes.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2133

    Last Modified: 16 Apr 2026

    Telindus 1100 ASDL router running firmware 6.0.x uses weak encryption for UDP session traffic, which allows remote attackers to gain unauthorized access by sniffing and decrypting the administrative password.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2127

    Last Modified: 16 Apr 2026

    Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2140

    Last Modified: 16 Apr 2026

    Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2142

    Last Modified: 16 Apr 2026

    An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2143

    Last Modified: 16 Apr 2026

    The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2144

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in BearShare 4.0.5 and 4.0.6 allows remote attackers to read files outside of the web root by hex-encoding the "/" (forward slash) or "." (dot) characters.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2150

    Last Modified: 16 Apr 2026

    Firewalls from multiple vendors empty state tables more slowly than they are filled, which allows remote attackers to flood state tables with packet flooding attacks such as (1) TCP SYN flood, (2) UDP flood, or (3) Crikey CRC Flood, which causes the firewall to refuse any new connections.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2153

    Last Modified: 16 Apr 2026

    Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers to execute arbitrary code.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2154

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2155

    Last Modified: 16 Apr 2026

    Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string specifiers in the name.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2156

    Last Modified: 16 Apr 2026

    Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2152

    Last Modified: 16 Apr 2026

    The Czech edition of Software602's Web Server before 2002.0.02.0916 allows remote attackers to gain administrator privileges via direct HTTP requests to the /admin/ directory, which is not password protected.

    Published: 31 Dec 2002
    Unknown

    CVE-2002-2151

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1651. Reason: This candidate is a duplicate of CVE-2002-1651. Notes: All CVE users should reference CVE-2002-1651 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2002
    4
    Medium

    CVE-2002-2163

    Last Modified: 16 Apr 2026

    KvPoll 1.1 allows remote authenticated users to vote more than once by setting the "already_voted" cookie by various methods, including a direct call to clear_cookies.php.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2164

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2165

    Last Modified: 16 Apr 2026

    The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2166

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2161

    Last Modified: 16 Apr 2026

    Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to cause a denial of service (hang and CPU consumption) via a SYN packet flood.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-2162

    Last Modified: 16 Apr 2026

    Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2173

    Last Modified: 16 Apr 2026

    Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a long DCC Chat message.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2176

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.

    Published: 31 Dec 2002
    4.9
    Medium

    CVE-2002-2188

    Last Modified: 16 Apr 2026

    OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error.

    Published: 31 Dec 2002
    5.1
    Medium

    CVE-2002-2189

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2190

    Last Modified: 16 Apr 2026

    ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2191

    Last Modified: 16 Apr 2026

    Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non-existent .nsf database, which leaks the version in the HTTP banner.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2192

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2209

    Last Modified: 16 Apr 2026

    Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2206

    Last Modified: 16 Apr 2026

    The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2207

    Last Modified: 16 Apr 2026

    Buffer overflow in ssldump 0.9b2 and earlier, when running in decryption mode, allows remote attackers to execute arbitrary code via a long RSA PreMasterSecret.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2216

    Last Modified: 16 Apr 2026

    Soft3304 04WebServer before 1.20 does not properly process URL strings, which allows remote attackers to obtain unspecified sensitive information.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2217

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) l parameter to customize.php or the (2) pg parameter to index.php.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2218

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impact, possibly gaining privileges or modifying critical configuration, via a CRLF sequence in a key value.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2219

    Last Modified: 16 Apr 2026

    chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1716

    Last Modified: 16 Apr 2026

    The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1718

    Last Modified: 16 Apr 2026

    Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claimed using an HTTP request for colegal.htm that contains .. (dot dot) sequences.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1719

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Bavo 0.3 allows remote attackers to modify posted messages.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1720

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1721

    Last Modified: 16 Apr 2026

    Off-by-one error in alterMIME 0.1.10 and 0.1.11 allows remote attackers to cause a denial of service (crash) via an x-header that causes snprintf overwrite the FFGET_FILE variable with a (null) byte.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1722

    Last Modified: 16 Apr 2026

    Logitech iTouch keyboards allows attackers with physical access to the system to bypass the screen locking function and execute user-defined commands that have been assigned to a button.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1717

    Last Modified: 16 Apr 2026

    Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /_vti_pvt/botinfs.cnf, (3) /_vti_pvt/bots.cnf, or (4) /_vti_pvt/linkinfo.cnf.

    Published: 31 Dec 2002
    6.8
    Medium

    CVE-2002-1729

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1731

    Last Modified: 16 Apr 2026

    The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF.

    Published: 31 Dec 2002