CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-1176

    Last Modified: 16 Apr 2026

    Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.

    Published: 20 Dec 2002
    7.5
    High

    CVE-2002-1177

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.

    Published: 20 Dec 2002
    7.5
    High

    CVE-2002-1393

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.

    Published: 20 Dec 2002
    7.5
    High

    CVE-2002-1643

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.

    Published: 19 Dec 2002
    6.2
    Medium

    CVE-2002-1366

    Last Modified: 16 Apr 2026

    Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.

    Published: 19 Dec 2002
    7.5
    High

    CVE-2002-1371

    Last Modified: 16 Apr 2026

    filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.

    Published: 19 Dec 2002
    10
    Critical

    CVE-2002-1369

    Last Modified: 16 Apr 2026

    jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

    Published: 19 Dec 2002
    7.5
    High

    CVE-2002-1363

    Last Modified: 16 Apr 2026

    Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.

    Published: 19 Dec 2002
    10
    Critical

    CVE-2002-1367

    Last Modified: 16 Apr 2026

    Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.

    Published: 19 Dec 2002
    7.5
    High

    CVE-2002-1368

    Last Modified: 16 Apr 2026

    Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.

    Published: 19 Dec 2002
    7.5
    High

    CVE-2002-1372

    Last Modified: 16 Apr 2026

    Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.

    Published: 19 Dec 2002
    10
    Critical

    CVE-2002-1383

    Last Modified: 16 Apr 2026

    Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.

    Published: 19 Dec 2002
    5
    Medium

    CVE-2002-1255

    Last Modified: 16 Apr 2026

    Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."

    Published: 18 Dec 2002
    Unknown

    CVE-2002-1161

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1380. Reason: This candidate is a reservation duplicate of CVE-2002-1380. Notes: none

    Published: 18 Dec 2002
    Unknown

    CVE-2002-1259

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1286. Reason: This candidate is a reservation duplicate of CVE-2002-1286. Notes: All CVE users should reference CVE-2002-1286 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Dec 2002
    4.6
    Medium

    CVE-2002-1349

    Last Modified: 16 Apr 2026

    Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).

    Published: 18 Dec 2002
    5
    Medium

    CVE-2002-1354

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.

    Published: 18 Dec 2002
    10
    Critical

    CVE-2002-1359

    Last Modified: 16 Apr 2026

    Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

    Published: 17 Dec 2002
    10
    Critical

    CVE-2002-1357

    Last Modified: 16 Apr 2026

    Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

    Published: 17 Dec 2002
    5
    Medium

    CVE-2002-1258

    Last Modified: 16 Apr 2026

    Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.

    Published: 17 Dec 2002
    10
    Critical

    CVE-2002-1358

    Last Modified: 16 Apr 2026

    Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

    Published: 17 Dec 2002
    10
    Critical

    CVE-2002-1360

    Last Modified: 16 Apr 2026

    Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.

    Published: 17 Dec 2002
    Unknown

    CVE-2002-1261

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1292. Reason: This candidate is a reservation duplicate of CVE-2002-1292. Notes: All CVE users should reference CVE-2002-1292 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Dec 2002
    5
    Medium

    CVE-2002-1345

    Last Modified: 16 Apr 2026

    Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

    Published: 17 Dec 2002
    2.1
    Low

    CVE-2002-1380

    Last Modified: 16 Apr 2026

    Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface.

    Published: 17 Dec 2002
    7.5
    High

    CVE-2002-1365

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local addresses.

    Published: 13 Dec 2002
    5
    Medium

    CVE-2002-1373

    Last Modified: 16 Apr 2026

    Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.

    Published: 12 Dec 2002
    7.5
    High

    CVE-2002-1376

    Last Modified: 16 Apr 2026

    libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 12 Dec 2002
    4.6
    Medium

    CVE-2002-1377

    Last Modified: 16 Apr 2026

    vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.

    Published: 12 Dec 2002
    7.5
    High

    CVE-2002-1374

    Last Modified: 16 Apr 2026

    The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.

    Published: 12 Dec 2002
    7.5
    High

    CVE-2002-1565

    Last Modified: 16 Apr 2026

    Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.

    Published: 12 Dec 2002
    7.5
    High

    CVE-2002-1375

    Last Modified: 16 Apr 2026

    The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.

    Published: 12 Dec 2002
    5
    Medium

    CVE-2002-1340

    Last Modified: 16 Apr 2026

    The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception.

    Published: 11 Dec 2002
    5
    Medium

    CVE-2002-1339

    Last Modified: 16 Apr 2026

    The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.

    Published: 11 Dec 2002
    5
    Medium

    CVE-2002-1338

    Last Modified: 16 Apr 2026

    The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.

    Published: 11 Dec 2002
    7.5
    High

    CVE-2002-1183

    Last Modified: 16 Apr 2026

    Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).

    Published: 11 Dec 2002
    2.1
    Low

    CVE-2002-1270

    Last Modified: 16 Apr 2026

    Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call.

    Published: 11 Dec 2002
    7.5
    High

    CVE-2002-1342

    Last Modified: 16 Apr 2026

    Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.

    Published: 11 Dec 2002
    7.5
    High

    CVE-2002-1262

    Last Modified: 16 Apr 2026

    Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files.

    Published: 11 Dec 2002
    4.6
    Medium

    CVE-2002-1268

    Last Modified: 16 Apr 2026

    Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."

    Published: 11 Dec 2002
    10
    Critical

    CVE-2002-1272

    Last Modified: 16 Apr 2026

    Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remote attackers to gain administrative privileges.

    Published: 11 Dec 2002
    4.6
    Medium

    CVE-2002-1266

    Last Modified: 16 Apr 2026

    Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File."

    Published: 11 Dec 2002
    5
    Medium

    CVE-2002-1267

    Last Modified: 16 Apr 2026

    Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing Web Administration utility, aka "CUPS Printing Web Administration is Remotely Accessible."

    Published: 11 Dec 2002
    5
    Medium

    CVE-2002-1185

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."

    Published: 11 Dec 2002
    5
    Medium

    CVE-2002-1186

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."

    Published: 11 Dec 2002
    6.8
    Medium

    CVE-2002-1187

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.

    Published: 11 Dec 2002
    6.4
    Medium

    CVE-2002-1188

    Last Modified: 16 Apr 2026

    Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."

    Published: 11 Dec 2002
    7.5
    High

    CVE-2002-1317

    Last Modified: 16 Apr 2026

    Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.

    Published: 11 Dec 2002
    7.5
    High

    CVE-2002-1396

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a denial of service or execute arbitrary code.

    Published: 10 Dec 2002
    5
    Medium

    CVE-2002-1344

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.

    Published: 10 Dec 2002