CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2002-1733

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web-based message board in Prospero Technologies allows remote attackers to inject arbitrary web script or HTML via a message board post.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1734

    Last Modified: 16 Apr 2026

    NewsPro 1.01 allows remote attackers to gain unauthorized administrator access by setting their authentication cookie to "logged,true".

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1730

    Last Modified: 16 Apr 2026

    ASPjar Guestbook 1.00 allows remote attackers to delete arbitrary messages accessing the delete.asp administrative script with certain cookie values set to "true".

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1748

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1750

    Last Modified: 16 Apr 2026

    csGuestbook.cgi in CGISCRIPT.NET csGuestbook 1.0 allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1751

    Last Modified: 16 Apr 2026

    csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1752

    Last Modified: 16 Apr 2026

    csChatRBox.cgi in CGIScript.net csChat-R-Box allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1760

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PHProjekt 2.0 through 3.1 allow remote attackers to execute arbitrary SQL commands via the unknown attack vectors.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1761

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in PHProjekt 2.0 through 3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1762

    Last Modified: 16 Apr 2026

    Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious active content such as ActiveX controls or Java.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1763

    Last Modified: 16 Apr 2026

    The dtscreen Sun Solaris 8 CDE screensaver crashes when the "Shift" and "Return" keys are pressed repeatedly and quickly, which allows local users to access the current session.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1764

    Last Modified: 16 Apr 2026

    acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1766

    Last Modified: 16 Apr 2026

    Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1759

    Last Modified: 16 Apr 2026

    The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers to cause PHProjekt to process arbitrary files.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1774

    Last Modified: 16 Apr 2026

    NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to send viruses that bypass the e-mail scanning via a NULL character in the MIME header before the virus. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the AutoProtect feature would detect the virus before it is executed

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1776

    Last Modified: 16 Apr 2026

    NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1789

    Last Modified: 16 Apr 2026

    Format string vulnerability in newsx NNTP client before 1.4.8 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a call to the syslog function.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1783

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.

    Published: 31 Dec 2002
    1.9
    Low

    CVE-2002-1785

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1786

    Last Modified: 16 Apr 2026

    SGI IRIX 6.5 through 6.5.14 applies a umask of 022 to root core dumps, which allows local users to read the core dumps and possibly obtain sensitive information.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1788

    Last Modified: 16 Apr 2026

    Format string vulnerability in the nn_exitmsg function in nn 6.6.0 through 6.6.3 allows remote NNTP servers to execute arbitrary code via format strings in server responses.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1794

    Last Modified: 16 Apr 2026

    Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1795

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1797

    Last Modified: 16 Apr 2026

    ChaiVM for HP color LaserJet 4500 and 4550 or HP LaserJet 4100 and 8150 does not properly enforce access control restrictions, which could allow local users to add, delete, or modify any services hosted by the ChaiServer.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1801

    Last Modified: 16 Apr 2026

    ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1803

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1804

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1806

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1807

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1802

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag when submitting news.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1814

    Last Modified: 16 Apr 2026

    Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1815

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in source.php and source.cgi in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1817

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Veritas Cluster Server (VCS) 1.2 for WindowsNT, Cluster Server 1.3.0 for Solaris, and Cluster Server 1.3.1 for HP-UX allows attackers to gain privileges via unknown attack vectors.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-1825

    Last Modified: 16 Apr 2026

    Format string vulnerability in PerlRTE_example1.pl in WASD 7.1, 7.2.0 through 7.2.3, and 8.0.0 allows remote attackers to execute arbitrary commands or crash the server via format strings in the $name variable.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1826

    Last Modified: 16 Apr 2026

    grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1827

    Last Modified: 16 Apr 2026

    Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1832

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1833

    Last Modified: 16 Apr 2026

    The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-1834

    Last Modified: 16 Apr 2026

    The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1835

    Last Modified: 16 Apr 2026

    The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1836

    Last Modified: 16 Apr 2026

    The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive files.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1854

    Last Modified: 16 Apr 2026

    Rlaj whois CGI script (whois.cgi) 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain name field.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1831

    Last Modified: 16 Apr 2026

    Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1840

    Last Modified: 16 Apr 2026

    irssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to access the system.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1841

    Last Modified: 16 Apr 2026

    The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1842

    Last Modified: 16 Apr 2026

    Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1843

    Last Modified: 16 Apr 2026

    Perlbot 1.9.2 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $text variable in SpelCheck.pm or (2) the $filename variable in HTMLPlog.pm.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1845

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1839

    Last Modified: 16 Apr 2026

    Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1850

    Last Modified: 16 Apr 2026

    mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.

    Published: 31 Dec 2002