CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2002-1895

    Last Modified: 16 Apr 2026

    The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attackers to cause a denial of service (crash) via a large number of HTTP GET requests for an MS-DOS device such as AUX, LPT1, CON, or PRN.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1905

    Last Modified: 16 Apr 2026

    Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1907

    Last Modified: 16 Apr 2026

    TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1908

    Last Modified: 16 Apr 2026

    Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1911

    Last Modified: 16 Apr 2026

    ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1926

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in source.php in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP query string.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-1927

    Last Modified: 16 Apr 2026

    Aquonics File Manager 1.5 allows users with edit privileges to modify user accounts by editing the userlist.cgi file.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1928

    Last Modified: 16 Apr 2026

    602Pro LAN SUITE 2002 allows remote attackers to view the directory tree via an HTTP GET request with a trailing "~" (tilde) or ".bak" extension.

    Published: 31 Dec 2002
    7.2
    High

    CVE-2002-1933

    Last Modified: 16 Apr 2026

    The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1941

    Last Modified: 16 Apr 2026

    Buffer overflow in RadioBird WebServer 4 Everyone 1.28 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request with the Host header set.

    Published: 31 Dec 2002
    4.3
    Medium

    CVE-2002-1950

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1959

    Last Modified: 16 Apr 2026

    Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1964

    Last Modified: 16 Apr 2026

    Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1966

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1979

    Last Modified: 16 Apr 2026

    WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-1998

    Last Modified: 16 Apr 2026

    Buffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to execute arbitrary commands via a long parameter to rtable_create (procedure 21).

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-1999

    Last Modified: 16 Apr 2026

    HP Praesidium Webproxy 1.0 running on HP-UX 11.04 VVOS could allow remote attackers to cause Webproxy to forward requests to the internal network via crafted HTTP requests.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2000

    Last Modified: 16 Apr 2026

    ACMS 4.3 and 4.4 in OpenVMS Alpha 7.2 and 7.3 does not properly use process privileges, which allows attackers to access data.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2008

    Last Modified: 16 Apr 2026

    Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2025

    Last Modified: 16 Apr 2026

    Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name.

    Published: 31 Dec 2002
    3.6
    Low

    CVE-2002-2038

    Last Modified: 16 Apr 2026

    Next Generation POSIX Threading (NGPT) 1.9.0 uses a filesystem-based shared memory entry, which allows local users to cause a denial of service or in threaded processes or spoof files via unknown methods.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2048

    Last Modified: 16 Apr 2026

    Buffer overflow in PFinger 0.7.8 client allows remote attackers to execute arbitrary code via a long query value passed to the (1) finger program, (2) -l, (3) -d, and (4) -t options. NOTE: if PFinger is not setuid or setgid, then this issue would not cross privilege boundaries and would not be considered a vulnerability.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2049

    Last Modified: 16 Apr 2026

    configure for Dsniff 2.3, fragroute 1.2, and fragrouter 1.6, when downloaded from monkey.org on May 17, 2002, has been modified to contain a backdoor, which allows remote attackers to access the system.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2058

    Last Modified: 16 Apr 2026

    TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2067

    Last Modified: 16 Apr 2026

    East-Tec Eraser 2002 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2080

    Last Modified: 16 Apr 2026

    Floositek FTGate PRO 1.05 allows remote attackers to cause a denial of service (memory and CPU consumption) via a large number of RCPT TO: messages during an SMTP session.

    Published: 31 Dec 2002
    7.5
    High

    CVE-2002-2082

    Last Modified: 16 Apr 2026

    FTGate and FTGate Pro 1.05 lock user mailboxes before authentication succeeds, which allows remote attackers to lock the mailboxes of other users.

    Published: 31 Dec 2002
    2.1
    Low

    CVE-2002-2093

    Last Modified: 16 Apr 2026

    The Video Control Panel on SGI O2/IRIX 6.5, when the Default Input is set to "Output Video", allows attackers to access a console session by running videoout then videoin.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2108

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the "VAIO Manual" software in certain Sony VAIO personal computers sold from November 2001 to January 2002, allows remote attackers to modify data via a web page or HTML e-mail.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2110

    Last Modified: 16 Apr 2026

    The RCA Digital Cable Modems DCM225 and DCM225E allow remote attackers to cause a denial of service (modem device reset) by connecting to port 80 on the 10.0.0.0/8 device.

    Published: 31 Dec 2002
    Unknown

    CVE-2002-2135

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1618. Reason: This candidate is a duplicate of CVE-2002-1618. Notes: All CVE users should reference CVE-2002-1618 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2002
    Unknown

    CVE-2002-2136

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1590. Reason: This candidate is a duplicate of CVE-2002-1590. Notes: All CVE users should reference CVE-2002-1590 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2138

    Last Modified: 16 Apr 2026

    RFC-NETBIOS in HP Advanced Server/9000 B.04.05 through B.04.09, when running HP-UX 11.00 or 11.11, allows remote attackers to cause a denial of service (panic) via a malformed UDP packet on port 139.

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2149

    Last Modified: 16 Apr 2026

    Buffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot) via a long HTTP request to the administrative interface.

    Published: 31 Dec 2002
    Unknown

    CVE-2002-2160

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1798. Reason: This candidate is a duplicate of CVE-2002-1798. Notes: All CVE users should reference CVE-2002-1798 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Dec 2002
    5
    Medium

    CVE-2002-2167

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an "include" function call.

    Published: 31 Dec 2002
    10
    Critical

    CVE-2002-1584

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.

    Published: 27 Dec 2002
    7.5
    High

    CVE-2002-1327

    Last Modified: 16 Apr 2026

    Buffer overflow in the Windows Shell function in Microsoft Windows XP allows remote attackers to execute arbitrary code via an .MP3 or .WMA audio file with a corrupt custom attribute, aka "Unchecked Buffer in Windows Shell Could Enable System Compromise."

    Published: 26 Dec 2002
    7.2
    High

    CVE-2002-1385

    Last Modified: 16 Apr 2026

    openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuration file that specifies additional code to be executed.

    Published: 26 Dec 2002
    5
    Medium

    CVE-2002-1351

    Last Modified: 16 Apr 2026

    Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request.

    Published: 24 Dec 2002
    7.2
    High

    CVE-2002-1381

    Last Modified: 16 Apr 2026

    Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.

    Published: 23 Dec 2002
    7.2
    High

    CVE-2002-1364

    Last Modified: 16 Apr 2026

    Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.

    Published: 23 Dec 2002
    10
    Critical

    CVE-2002-1257

    Last Modified: 16 Apr 2026

    Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.

    Published: 23 Dec 2002
    10
    Critical

    CVE-2002-1361

    Last Modified: 16 Apr 2026

    overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.

    Published: 23 Dec 2002
    7.5
    High

    CVE-2002-1382

    Last Modified: 16 Apr 2026

    Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846.

    Published: 23 Dec 2002
    5
    Medium

    CVE-2002-1256

    Last Modified: 16 Apr 2026

    The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.

    Published: 23 Dec 2002
    7.5
    High

    CVE-2002-1260

    Last Modified: 16 Apr 2026

    The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.

    Published: 23 Dec 2002
    7.2
    High

    CVE-2002-1296

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

    Published: 23 Dec 2002
    5
    Medium

    CVE-2002-1325

    Last Modified: 16 Apr 2026

    Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."

    Published: 23 Dec 2002
    7.2
    High

    CVE-2002-1384

    Last Modified: 16 Apr 2026

    Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.

    Published: 23 Dec 2002