CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-1930

    Last Modified: 16 Apr 2026

    Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1932

    Last Modified: 16 Apr 2026

    Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1934

    Last Modified: 16 Apr 2026

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of the Admin password, MD5 hash of the physical password, and other registration information.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1942

    Last Modified: 16 Apr 2026

    Imatix Xitami 2.5 b5 does not properly terminate certain Keep-Alive connections that have been broken or closed early, which allows remote attackers to cause a denial of service (crash) via a large number of concurrent sessions.

    Published: 31 Dec 2002
    5.5
    Medium

    CVE-2002-1946

    Last Modified: 16 Apr 2026

    Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows local users to obtain and decrypt the password.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1949

    Last Modified: 16 Apr 2026

    The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1953

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1962

    Last Modified: 16 Apr 2026

    Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL with an IP address instead of a hostname.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1963

    Last Modified: 16 Apr 2026

    Linux kernel 2.4.1 through 2.4.19 sets root's NR_RESERVED_FILES limit to 10 files, which allows local users to cause a denial of service (resource exhaustion) by opening 10 setuid binaries.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1965

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web script or HTML via the (1) Javascript events, as demonstrated via an onerror event in an IMG SRC tag or (2) User-Agent field in an HTTP GET request.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1973

    Last Modified: 16 Apr 2026

    Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1974

    Last Modified: 16 Apr 2026

    The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.

    Published: 31 Dec 2002
    5.5
    Medium

    CVE-2002-1975

    Last Modified: 16 Apr 2026

    Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1985

    Last Modified: 16 Apr 2026

    iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long "MAIL FROM" command, possibly triggering a buffer overflow.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1986

    Last Modified: 16 Apr 2026

    Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1989

    Last Modified: 16 Apr 2026

    Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp.

    Published: 31 Dec 2002
    1.2
    Low

    CVE-2002-2001

    Last Modified: 16 Apr 2026

    jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2006

    Last Modified: 16 Apr 2026

    The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2007

    Last Modified: 16 Apr 2026

    The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-2022

    Last Modified: 16 Apr 2026

    Format string vulnerability in Kaffe OpenVM 1.0.6 and earlier allows local users to execute arbitrary code, when a java.lang.NoClassDefFoundError is thrown, via format specifiers in the forName attribute.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2023

    Last Modified: 16 Apr 2026

    The get_parameter_from_freqency_source function in beep2 1.0, 1.1 and 1.2, when installed setuid root, allows local users to read arbitrary files via unknown attack vectors.

    Published: 31 Dec 2002
    5.3
    Medium

    CVE-2002-2024

    Last Modified: 16 Apr 2026

    Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2028

    Last Modified: 16 Apr 2026

    The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2029

    Last Modified: 16 Apr 2026

    PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2031

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event handler to monitor the results.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2037

    Last Modified: 16 Apr 2026

    The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris 2.6 with unnecessary services and without the latest security patches, which allows attackers to exploit known vulnerabilities.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2039

    Last Modified: 16 Apr 2026

    /bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2046

    Last Modified: 16 Apr 2026

    x_news.php in X-News (x_news) 1.1 and earlier allows remote attackers to gain administrative privileges by stealing and replaying the md5_password cookie.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-2047

    Last Modified: 16 Apr 2026

    The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postscript (EPS) file.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2050

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a .. (dot dot) in the hostname of a log entry.

    Published: 31 Dec 2002
    4.6
    Medium

    CVE-2002-2059

    Last Modified: 16 Apr 2026

    BIOS D845BG, D845HV, D845PT and D845WN on Intel motherboards does not properly restrict access to configuration information when BIOS passwords are enabled, which could allow local users to change the default boot device via the F8 key.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2062

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2068

    Last Modified: 16 Apr 2026

    Eraser 5.3 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2073

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2075

    Last Modified: 16 Apr 2026

    ICQ 2001a and 2002b allows remote attackers to cause a denial of service (memory consumption and hang) via a contact message with a large contacts number.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2077

    Last Modified: 16 Apr 2026

    The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2078

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Floositek (1) FTGate Pro 1.05 and (2) FTGate Office 1.05 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long POP3 APOP USER command.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2079

    Last Modified: 16 Apr 2026

    mosix-protocol-stack in Multicomputer Operating System for UnIX (MOSIX) 1.5.7 allows remote attackers to cause a denial of service via malformed packets.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2081

    Last Modified: 16 Apr 2026

    cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2091

    Last Modified: 16 Apr 2026

    Format string vulnerability in Deception Finger Daemon, decfingerd, 0.7 may allow remote attackers to execute arbitrary code via the username of a finger request.

    Published: 31 Dec 2002
    3.7
    Low

    CVE-2002-2092

    Last Modified: 16 Apr 2026

    Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2107

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the lookup script in Veridis OpenKeyServer (OKS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2109

    Last Modified: 16 Apr 2026

    Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2111

    Last Modified: 16 Apr 2026

    Fwmon before 1.0.10 allows remote attackers to cause a denial of service (crash) by causing the kernel to return a large packet.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2117

    Last Modified: 16 Apr 2026

    Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP).

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2125

    Last Modified: 16 Apr 2026

    Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate is in the user's local repository, which could allow remote attackers to decrypt web sessions via a man-in-the-middle (MITM) attack.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2126

    Last Modified: 16 Apr 2026

    restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2134

    Last Modified: 16 Apr 2026

    haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web server that contains the code in a lang.php file.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2137

    Last Modified: 16 Apr 2026

    GlobalSunTech Wireless Access Points (1) WISECOM GL2422AP-0T, and possibly OEM products such as (2) D-Link DWL-900AP+ B1 2.1 and 2.2, (3) ALLOY GL-2422AP-S, (4) EUSSO GL2422-AP, and (5) LINKSYS WAP11-V2.2, allow remote attackers to obtain sensitive information like WEP keys, the administrator password, and the MAC filter via a "getsearch" request to UDP port 27155.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2139

    Last Modified: 16 Apr 2026

    Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.

    Published: 31 Dec 2002