CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2002-2211

    Last Modified: 16 Apr 2026

    BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2226

    Last Modified: 16 Apr 2026

    Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2231

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL in a photo URL or (2) an X-Forwarded-For: header.

    Published: 31 Dec 2002
    8.3
    High

    CVE-2002-2233

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2240

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2249

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2259

    Last Modified: 16 Apr 2026

    Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2267

    Last Modified: 16 Apr 2026

    bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2276

    Last Modified: 16 Apr 2026

    Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message.

    Published: 31 Dec 2002
    6.9
    Medium

    CVE-2002-2282

    Last Modified: 16 Apr 2026

    McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2294

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed RealAudio (rad) packets that are not properly handled by the RealAudio Proxy, or (2) crafted packets to the statistics service (statsd).

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2302

    Last Modified: 16 Apr 2026

    3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2311

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this issue.

    Published: 31 Dec 2002
    5.8
    Medium

    CVE-2002-2312

    Last Modified: 16 Apr 2026

    Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2340

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in read.php in Phorum 3.3.2a allows remote attackers to inject arbitrary web script or HTML via (1) the t parameter or (2) the body of an email response.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2356

    Last Modified: 16 Apr 2026

    HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2364

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2365

    Last Modified: 16 Apr 2026

    Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2369

    Last Modified: 16 Apr 2026

    Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2375

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding directory structure than is already available to any CommuniGate Pro user, although there is a possibility that it could be used to infer product version information.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2387

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2388

    Last Modified: 16 Apr 2026

    Buffer overflow in INweb POP3 mail server 2.01 allows remote attackers to cause a denial of service (crash) via a long HELO command.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2390

    Last Modified: 16 Apr 2026

    Buffer overflow in the IDENT daemon (identd) in Trillian 0.6351, 0.725, 0.73, 0.74 and 1.0 pro allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2402

    Last Modified: 16 Apr 2026

    SURECOM broadband router EP-4501 uses a default SNMP read community string of "public" and a default SNMP read/write community string of "secret," which allows remote attackers to read and modify router configuration information.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2411

    Last Modified: 16 Apr 2026

    Buffer overflow in badmin.c in BannerWheel 1.0 allows remote attackers to execute arbitrary code via a long rcmd command.

    Published: 31 Dec 2002
    7.8
    High

    CVE-2002-2421

    Last Modified: 16 Apr 2026

    acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1387

    Last Modified: 16 Apr 2026

    The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1623

    Last Modified: 16 Apr 2026

    The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2) sniffing, as originally reported for FireWall-1 SecuRemote.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1627

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in quiz.cgi for Mike Spice Quiz Me! before 0.6 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the quiz parameter.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1630

    Last Modified: 16 Apr 2026

    The sendmail.jsp sample page in Oracle 9i Application Server (9iAS) allows remote attackers to send arbitrary emails.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1631

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-1632

    Last Modified: 16 Apr 2026

    Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-1633

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in QNX 4.25 may allow local users to execute arbitrary code via long command line arguments to (1) sample, (2) ex, (3) du, (4) find, (5) lex, (6) mkdir, (7) rm, (8) serserv, (9) tcpserv, (10) termdef, (11) time, (12) unzip, (13) use, (14) wcc, (15) wcc386, (16) wd, (17) wdisasm, (18) which, (19) wlib, (20) wlink, (21) wpp, (22) wpp386, (23) wprof, (24) write, or (25) wstrip.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1634

    Last Modified: 16 Apr 2026

    Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl, (5) volscgi.pl, (6) lancgi.pl, (7) test.jse, or (8) env.pl.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1635

    Last Modified: 16 Apr 2026

    The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1657

    Last Modified: 16 Apr 2026

    PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-1664

    Last Modified: 16 Apr 2026

    Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1667

    Last Modified: 16 Apr 2026

    The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to cause a denial of service (crash) by calling msync on an unaccessed memory map created with MAP_ANON and MAP_NOSYNC flags.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1668

    Last Modified: 16 Apr 2026

    HP-UX 11.11 and earlier allows local users to cause a denial of service (kernel deadlock), due to a "file system weakness" that is possibly via an mmap() system call and performing an I/O operation using data from the mapped buffer on the file descriptor for the mapped file.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1678

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 through 2.2.4 allows remote attackers to steal authentication credentials by injecting script into $letterbits.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1680

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CGI Online Worldweb Shopping 1.1 (a.k.a. COWS) allows remote attackers to execute arbitrary script as other users by injecting script into (1) diagnose.cgi or (2) compatible.cgi.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1685

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1690

    Last Modified: 16 Apr 2026

    Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.

    Published: 31 Dec 2002
    5.5
    Medium

    CVE-2002-1696

    Last Modified: 16 Apr 2026

    Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1699

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1700

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1704

    Last Modified: 16 Apr 2026

    Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1706

    Last Modified: 16 Apr 2026

    Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data Over Cable Service Interface Specification (DOCSIS) settings via a DOCSIS file without a Message Integrity Check (MIC) signature, which is approved by the router.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-1709

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1715

    Last Modified: 16 Apr 2026

    SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then executing that script to gain normal shell access.

    Published: 31 Dec 2002