CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-2141

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation of the intended restrictions.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2145

    Last Modified: 16 Apr 2026

    Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a '.' (%2e) at the end of the filename.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2148

    Last Modified: 16 Apr 2026

    Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information in the response.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2158

    Last Modified: 16 Apr 2026

    zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2169

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2170

    Last Modified: 16 Apr 2026

    Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2171

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2172

    Last Modified: 16 Apr 2026

    Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information.

    Published: 31 Dec 2002
    2.6
    Low

    CVE-2002-2177

    Last Modified: 16 Apr 2026

    BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2178

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2187

    Last Modified: 16 Apr 2026

    Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-2193

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter.

    Published: 31 Dec 2002
    5.5
    Medium

    CVE-2002-1739

    Last Modified: 16 Apr 2026

    Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1740

    Last Modified: 16 Apr 2026

    Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter).

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1741

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1742

    Last Modified: 16 Apr 2026

    SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1744

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1753

    Last Modified: 16 Apr 2026

    csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1754

    Last Modified: 16 Apr 2026

    Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1755

    Last Modified: 16 Apr 2026

    tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.

    Published: 31 Dec 2002
    6.4
    Medium

    CVE-2002-2045

    Last Modified: 16 Apr 2026

    x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which leaks the pathname in an error message.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1617

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in HP Tru64 UNIX 5.x allow local users to execute arbitrary code via (1) a long -contextDir argument to dtaction, (2) a long -p argument to dtprintinfo, (3) a long -customization argument to dxterm, or (4) a long DISPLAY environment variable to dtterm.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1628

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in vote.cgi for Mike Spice Mike's Vote CGI before 1.3 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the type parameter.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1629

    Last Modified: 16 Apr 2026

    Multi-Tech ProxyServer products MTPSR1-100, MTPSR1-120, MTPSR1-202ST, MTPSR2-201, and MTPSR3-200 ship with a null password, which allows remote attackers to gain administrative privileges via Telnet or HTTP.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1652

    Last Modified: 16 Apr 2026

    Buffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long query parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1663

    Last Modified: 16 Apr 2026

    The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1665

    Last Modified: 16 Apr 2026

    Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long set_buddygrp field.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1666

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Oracle E-Business Suite 11i.1 through 11i.6 allows remote attackers to execute unauthorized PL/SQL procedures by modifying the Oracle Applications URL.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1677

    Last Modified: 16 Apr 2026

    14all.cgi 1.1p15 in mrtgconfig allows remote attackers to determine the physical path to the web root directory via a request with an invalid cfg parameter, which generates an error message that reveals the path.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1679

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 2.2.0 allows remote attackers to execute arbitrary script as other users by injecting script into a bulletin board message.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1689

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1698

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1707

    Last Modified: 16 Apr 2026

    install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir parameter to reference a URL on a remote web server that contains the code.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1732

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Actinic Catalog 4.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string argument to certain .pl files, (2) the REFPAGE parameter to ca000007.pl, (3) PRODREF parameter to ss000007.pl, or (4) hop parameter to ca000001.pl.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1756

    Last Modified: 16 Apr 2026

    ACDSee 4.0 allows remote attackers to cause a denial of service (crash) via an .ais file with a long file description field, which is not properly handled when the file properties of the file are viewed.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1757

    Last Modified: 16 Apr 2026

    PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, which is included in the PATH_INFO portion of the $PHP_SELF variable, as demonstrated using "mail_send.php/sms".

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1758

    Last Modified: 16 Apr 2026

    PHProjekt 2.0 through 3.1 allows remote attackers to view or modify data via requests to certain scripts that do not verify if the user is logged in.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1771

    Last Modified: 16 Apr 2026

    Matt Wright FormMail 1.9 and earlier allows remote attackers to send spam or anonymous e-mail by injecting a newline character followed by CC:, BCC:, or additional TO: fields in the email and realname CGI variables.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1779

    Last Modified: 16 Apr 2026

    The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305).

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1781

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in DeleGate 7.7.0 through 7.8.1 allow remote attackers to execute arbitrary code, as demonstrated using a long USER command to the POP proxy.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1791

    Last Modified: 16 Apr 2026

    SGI IRIX 6.5 through 6.5.17 creates temporary desktop files with world-writable permissions, which allows local users to overwrite or corrupt those files.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1799

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email parameter to add.php or (2) banurl parameter.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1811

    Last Modified: 16 Apr 2026

    Belkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of service (connection loss) by sending several SNMP GetNextRequest requests.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1830

    Last Modified: 16 Apr 2026

    Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1838

    Last Modified: 16 Apr 2026

    Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1847

    Last Modified: 16 Apr 2026

    Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1864

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1873

    Last Modified: 16 Apr 2026

    Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1892

    Last Modified: 16 Apr 2026

    NETGEAR FVS318 running firmware 1.1 stores the username and password in a readable format when a backup of the configuration file is made, which allows local users to obtain sensitive information.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1893

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary web script or HTML via the e-mail message.

    Published: 31 Dec 2002