CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2002-1347

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

    Published: 9 Dec 2002
    7.5
    High

    CVE-2002-1356

    Last Modified: 16 Apr 2026

    Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages.

    Published: 7 Dec 2002
    5
    Medium

    CVE-2002-1355

    Last Modified: 16 Apr 2026

    Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages.

    Published: 7 Dec 2002
    1.2
    Low

    CVE-2002-1508

    Last Modified: 16 Apr 2026

    slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.

    Published: 6 Dec 2002
    7.5
    High

    CVE-2002-1379

    Last Modified: 16 Apr 2026

    OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges.

    Published: 6 Dec 2002
    7.5
    High

    CVE-2002-1378

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file that is not properly handled by getfilter functions, (3) a malicious ldaptemplates.conf that causes an overflow in libldap, (4) a certain access control list that causes an overflow in slapd, or (5) a long generated filename for logging rejected replication requests.

    Published: 6 Dec 2002
    2.1
    Low

    CVE-2002-1587

    Last Modified: 16 Apr 2026

    The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.

    Published: 4 Dec 2002
    4.6
    Medium

    CVE-2002-1269

    Last Modified: 16 Apr 2026

    Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem.

    Published: 3 Dec 2002
    2.1
    Low

    CVE-2002-1586

    Last Modified: 16 Apr 2026

    Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.

    Published: 3 Dec 2002
    6.8
    Medium

    CVE-2002-1334

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

    Published: 3 Dec 2002
    6.8
    Medium

    CVE-2002-1341

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.

    Published: 3 Dec 2002
    6.4
    Medium

    CVE-2002-1159

    Last Modified: 16 Apr 2026

    Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.

    Published: 2 Dec 2002
    7.2
    High

    CVE-2002-1158

    Last Modified: 16 Apr 2026

    Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.

    Published: 2 Dec 2002
    4.6
    Medium

    CVE-2002-1284

    Last Modified: 16 Apr 2026

    The wizard in KGPG 0.6 through 0.8.2 does not properly provide the passphrase to gpg when creating new keys, which causes secret keys to be created with an empty passphrase and allows local attackers to steal the keys if they can be read.

    Published: 29 Nov 2002
    6.8
    Medium

    CVE-2002-1307

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.

    Published: 29 Nov 2002
    7.5
    High

    CVE-2002-1219

    Last Modified: 16 Apr 2026

    Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).

    Published: 29 Nov 2002
    7.5
    High

    CVE-2002-1142

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.

    Published: 29 Nov 2002
    5
    Medium

    CVE-2002-1220

    Last Modified: 16 Apr 2026

    BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.

    Published: 29 Nov 2002
    5
    Medium

    CVE-2002-1221

    Last Modified: 16 Apr 2026

    BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.

    Published: 29 Nov 2002
    4.6
    Medium

    CVE-2002-1311

    Last Modified: 16 Apr 2026

    Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files.

    Published: 29 Nov 2002
    2.1
    Low

    CVE-2002-1313

    Last Modified: 16 Apr 2026

    nullmailer 1.00RC5 and earlier allows local users to cause a denial of service via an email to a local user that does not exist, which generates an error that causes nullmailer to stop sending mail to all users.

    Published: 29 Nov 2002
    5
    Medium

    CVE-2002-1588

    Last Modified: 16 Apr 2026

    Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2 allows remote attackers to cause a denial of service (mailtool segmentation violation and crash) via a malformed mail attachment.

    Published: 29 Nov 2002
    7.5
    High

    CVE-2002-1254

    Last Modified: 16 Apr 2026

    Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."

    Published: 27 Nov 2002
    7.5
    High

    CVE-2002-1321

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u file, or (3) certain "Now Playing" options on a downloaded file with a long filename.

    Published: 27 Nov 2002
    5
    Medium

    CVE-2002-1322

    Last Modified: 16 Apr 2026

    Rational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain packets to port 371, e.g. via nmap.

    Published: 27 Nov 2002
    5
    Medium

    CVE-2002-1348

    Last Modified: 16 Apr 2026

    w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.

    Published: 27 Nov 2002
    4.3
    Medium

    CVE-2002-1335

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.

    Published: 27 Nov 2002
    10
    Critical

    CVE-2002-1645

    Last Modified: 16 Apr 2026

    Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.

    Published: 25 Nov 2002
    7.2
    High

    CVE-2002-1644

    Last Modified: 16 Apr 2026

    SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain privileges.

    Published: 25 Nov 2002
    7.5
    High

    CVE-2002-1391

    Last Modified: 16 Apr 2026

    Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Caller ID string with a long CallerName argument.

    Published: 25 Nov 2002
    2.1
    Low

    CVE-2002-1392

    Last Modified: 16 Apr 2026

    faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to modify fax transmission privileges.

    Published: 25 Nov 2002
    6.8
    Medium

    CVE-2002-1316

    Last Modified: 16 Apr 2026

    importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).

    Published: 21 Nov 2002
    5
    Medium

    CVE-2002-1204

    Last Modified: 16 Apr 2026

    Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

    Published: 21 Nov 2002
    5
    Medium

    CVE-2002-1210

    Last Modified: 16 Apr 2026

    Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context.

    Published: 21 Nov 2002
    6.8
    Medium

    CVE-2002-1315

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).

    Published: 21 Nov 2002
    7.5
    High

    CVE-2002-1309

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary via an HTTP GET request with a long .cfm file name.

    Published: 21 Nov 2002
    7.5
    High

    CVE-2002-1310

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name.

    Published: 21 Nov 2002
    5
    Medium

    CVE-2002-1312

    Last Modified: 16 Apr 2026

    Buffer overflow in the Web management interface in Linksys BEFW11S4 wireless access point router 2 and BEFSR11, BEFSR41, and BEFSRU31 EtherFast Cable/DSL routers with firmware before 1.43.3 with remote management enabled allows remote attackers to cause a denial of service (router crash) via a long password.

    Published: 20 Nov 2002
    10
    Critical

    CVE-2002-1318

    Last Modified: 16 Apr 2026

    Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.

    Published: 20 Nov 2002
    7.5
    High

    CVE-2002-1286

    Last Modified: 16 Apr 2026

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.

    Published: 14 Nov 2002
    7.5
    High

    CVE-2002-1292

    Last Modified: 16 Apr 2026

    The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.

    Published: 14 Nov 2002
    5
    Medium

    CVE-2002-1287

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.

    Published: 14 Nov 2002
    5
    Medium

    CVE-2002-1288

    Last Modified: 16 Apr 2026

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call.

    Published: 14 Nov 2002
    7.5
    High

    CVE-2002-1289

    Last Modified: 16 Apr 2026

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters.

    Published: 14 Nov 2002
    7.5
    High

    CVE-2002-1294

    Last Modified: 16 Apr 2026

    The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.

    Published: 14 Nov 2002
    7.5
    High

    CVE-2002-1295

    Last Modified: 16 Apr 2026

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."

    Published: 14 Nov 2002
    7.2
    High

    CVE-2002-1279

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option).

    Published: 14 Nov 2002
    6.4
    Medium

    CVE-2002-1290

    Last Modified: 16 Apr 2026

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class.

    Published: 14 Nov 2002
    5
    Medium

    CVE-2002-1291

    Last Modified: 16 Apr 2026

    The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.

    Published: 14 Nov 2002
    7.5
    High

    CVE-2002-1293

    Last Modified: 16 Apr 2026

    The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.

    Published: 14 Nov 2002