CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-1851

    Last Modified: 16 Apr 2026

    Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1852

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1853

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the subject of a newsgroup post, which is not properly handled by (1) myarticles.php, (2) search.php, (3) stats.php, or (4) standard.lib.php.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1858

    Last Modified: 16 Apr 2026

    Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1859

    Last Modified: 16 Apr 2026

    Orion Application Server 1.5.3, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1860

    Last Modified: 16 Apr 2026

    Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1861

    Last Modified: 16 Apr 2026

    Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1862

    Last Modified: 16 Apr 2026

    SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1868

    Last Modified: 16 Apr 2026

    Dispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields.

    Published: 31 Dec 2002
    3.3
    Low

    CVE-2002-1869

    Last Modified: 16 Apr 2026

    Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1870

    Last Modified: 16 Apr 2026

    Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1875

    Last Modified: 16 Apr 2026

    Entercept Agent 2.5 agent for Windows, released before May 21, 2002, allows local administrative users to obtain the entercept agent password, which could allow the administrators to log on as the entercept_agent account and conceal their identity.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1876

    Last Modified: 16 Apr 2026

    Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1877

    Last Modified: 16 Apr 2026

    NETGEAR FM114P allows remote attackers to bypass access restrictions for web sites via a URL that uses the IP address instead of the hostname.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1878

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1881

    Last Modified: 16 Apr 2026

    Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ROT13 encoding the body of the file but not the headers.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1882

    Last Modified: 16 Apr 2026

    Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1874

    Last Modified: 16 Apr 2026

    astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.

    Published: 31 Dec 2002
    5.5
    Medium

    CVE-2002-1915

    Last Modified: 16 Apr 2026

    tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1916

    Last Modified: 16 Apr 2026

    Pirch and RusPirch, when auto-log is enabled, allows remote attackers to cause a denial of service (crash) via a nickname containing an MS-DOS device name such as AUX, which is inserted into a filename for saving queries.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1917

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1918

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1935

    Last Modified: 16 Apr 2026

    Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1936

    Last Modified: 16 Apr 2026

    UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field", (2) guru account with a password of "*3noguru", (3) snmp account with a password of "snmp", or (4) dbase account with a password of "dbase".

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1937

    Last Modified: 16 Apr 2026

    Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1938

    Last Modified: 16 Apr 2026

    Virgil CGI Scanner 0.9 allows remote attackers to execute arbitrary commands via the (1) tar (TARGET) or (2) zielport (ZIELPORT) parameters.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1939

    Last Modified: 16 Apr 2026

    FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1943

    Last Modified: 16 Apr 2026

    SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a response to a passive mode (PASV) file transfer request.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1944

    Last Modified: 16 Apr 2026

    Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1945

    Last Modified: 16 Apr 2026

    Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SMTP) or (2) TCP port 110 (POP3).

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-1947

    Last Modified: 16 Apr 2026

    Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1948

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1954

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1955

    Last Modified: 16 Apr 2026

    Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1956

    Last Modified: 16 Apr 2026

    ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1957

    Last Modified: 16 Apr 2026

    Buffer overflow in the netlog function in pen.c for Pen 0.9.1 and 0.9.2 allows remote attackers to execute arbitrary commands via malformed log messages.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1951

    Last Modified: 16 Apr 2026

    Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1952

    Last Modified: 16 Apr 2026

    phpRank 1.8 does not properly check the return codes for MySQL operations when authenticating users, which could allow remote attackers to authenticate using a NULL password when database errors occur or if the database is unavailable.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1968

    Last Modified: 16 Apr 2026

    Com21 DOXport 1100 series cable modem running firmware 2.1.1.106, and possibly other versions before 2.1.1.108.003, downloads a DOCSIS configuration file from a TFTP server running on the internal network, which allows local users to modify configuration of the modem via a malicious TFTP server.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1650

    Last Modified: 16 Apr 2026

    The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modified sqspell_command parameter.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1660

    Last Modified: 16 Apr 2026

    calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1654

    Last Modified: 16 Apr 2026

    iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1655

    Last Modified: 16 Apr 2026

    The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1656

    Last Modified: 16 Apr 2026

    X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1658

    Last Modified: 16 Apr 2026

    Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1653

    Last Modified: 16 Apr 2026

    Farm9 Cryptcat, when started in server mode with the -e option, does not enable encryption, which allows clients to communicate without encryption despite intended configuration, and may allow remote attackers to sniff sensitive information.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1670

    Last Modified: 16 Apr 2026

    Microsoft Windows XP Professional upgrade edition overwrites previously installed patches for Internet Explorer 6.0, leaving Internet Explorer unpatched.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1671

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of the clipboard via the getData method of the clipboardData object.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1672

    Last Modified: 16 Apr 2026

    Webmin 0.92, when installed from an RPM, creates /var/webmin with insecure permissions (world readable), which could allow local users to read the root user's cookie-based authentication credentials and possibly hijack the root user's session using the credentials.

    Published: 31 Dec 2002
    3.6
    Low

    CVE-2002-1673

    Last Modified: 16 Apr 2026

    The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows local users to execute script and possibly steal cookies by inserting the script into certain files or fields, such as a real user name entry in the passwd file.

    Published: 31 Dec 2002