CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2002-1686

    Last Modified: 16 Apr 2026

    Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1669

    Last Modified: 16 Apr 2026

    pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation.

    Published: 31 Dec 2002
    6.8
    Medium

    CVE-2002-1681

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragraph <P> tag.

    Published: 31 Dec 2002
    5.5
    Medium

    CVE-2002-1682

    Last Modified: 16 Apr 2026

    NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1683

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1684

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents.

    Published: 31 Dec 2002
    3.6
    Low

    CVE-2002-1692

    Last Modified: 16 Apr 2026

    Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1694

    Last Modified: 16 Apr 2026

    Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1695

    Last Modified: 16 Apr 2026

    Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1702

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter.

    Published: 31 Dec 2002
    6.8
    Medium

    CVE-2002-1703

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users via the Term parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1705

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1735

    Last Modified: 16 Apr 2026

    Buffer overflow in dlogin 1.0a could allow local users to gain privileges via unknown attack vectors.

    Published: 31 Dec 2002
    3.6
    Low

    CVE-2002-1710

    Last Modified: 16 Apr 2026

    The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1711

    Last Modified: 16 Apr 2026

    BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1712

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.

    Published: 31 Dec 2002
    5.5
    Medium

    CVE-2002-1713

    Last Modified: 16 Apr 2026

    The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1649

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in read_body.php in SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary Javascript via a javascript: URL in an IMG tag.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1648

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1647

    Last Modified: 16 Apr 2026

    The quick login feature in Slash Slashcode does not redirect the user to an alternate URL when the wrong password is provided, which makes it easier for remote web sites to guess the proper passwords by reading the username and password from the Referrer URL.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1646

    Last Modified: 16 Apr 2026

    SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1636

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server (9iAS) allows remote attackers to inject arbitrary web script or HTML via the cbuf parameter to htp.print.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1625

    Last Modified: 16 Apr 2026

    Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of service (bandwidth, resource, and CPU consumption) via the (1) loadMovie or (2) loadSound commands, which continue to execute until the browser is closed.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1624

    Last Modified: 16 Apr 2026

    Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1622

    Last Modified: 16 Apr 2026

    Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1659

    Last Modified: 16 Apr 2026

    user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1386

    Last Modified: 16 Apr 2026

    Buffer overflow in traceroute-nanog (aka traceroute-ng) may allow local users to execute arbitrary code via a long hostname argument.

    Published: 31 Dec 2002
    Unknown

    CVE-2002-2157

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1660. Reason: This candidate is a duplicate of CVE-2002-1660. Notes: All CVE users should reference CVE-2002-1660 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2398

    Last Modified: 16 Apr 2026

    The new thread posting page in APBoard 2.02 and 2.03 allows remote attackers to post messages to protected forums by modifying the insertinto parameter.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2281

    Last Modified: 16 Apr 2026

    Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2280

    Last Modified: 16 Apr 2026

    syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2183

    Last Modified: 16 Apr 2026

    phpShare.php in phpShare before 0.6 beta 3 allows remote attackers to include and execute arbitrary PHP scripts from remote servers.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2182

    Last Modified: 16 Apr 2026

    Buffer overflow in Seunghyun Seo's MSN666 MSN Sniffer 1.0 and 1.0.1 allows remote attackers to execute arbitrary code via a long MSN packet.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1980

    Last Modified: 16 Apr 2026

    Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-1883

    Last Modified: 16 Apr 2026

    Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTML pages and cause a denial of service.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1880

    Last Modified: 16 Apr 2026

    LokwaBB 1.2.2 allows remote attackers to read arbitrary messages by modifying the pmid parameter to pm.php.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1787

    Last Modified: 16 Apr 2026

    Buffer overflow in uux in eoe.sw.uucp package of SGI IRIX 6.5 through 6.5.17 allows local users to execute arbitrary code via unknown attack vectors.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-2089

    Last Modified: 16 Apr 2026

    Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2426

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2423

    Last Modified: 16 Apr 2026

    Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2422

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2420

    Last Modified: 16 Apr 2026

    site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2412

    Last Modified: 16 Apr 2026

    Winamp 2.80 stores authentication credentials in plaintext in the (1) [HTTP-AUTH] and (2) [winamp] sections in winamp.ini, which allows local users to gain access to other accounts.

    Published: 31 Dec 2002
    6.9
    Medium

    CVE-2002-2407

    Last Modified: 16 Apr 2026

    Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2403

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.

    Published: 31 Dec 2002
    3.6
    Low

    CVE-2002-2401

    Last Modified: 16 Apr 2026

    NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2389

    Last Modified: 16 Apr 2026

    TheServer 1.74 web server stores server.ini under the web document root with insufficient access control, which allows remote attackers to obtain cleartext passwords and gain access to server log files.

    Published: 31 Dec 2002
    3.6
    Low

    CVE-2002-2384

    Last Modified: 16 Apr 2026

    hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2377

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2376

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue might overlap CVE-2005-1605.

    Published: 31 Dec 2002