CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2002-1283

    Last Modified: 16 Apr 2026

    Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.

    Published: 14 Nov 2002
    7.2
    High

    CVE-2002-1285

    Last Modified: 16 Apr 2026

    runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.

    Published: 14 Nov 2002
    7.5
    High

    CVE-2002-1308

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.

    Published: 14 Nov 2002
    7.2
    High

    CVE-2002-1253

    Last Modified: 16 Apr 2026

    Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1264

    Last Modified: 16 Apr 2026

    Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.

    Published: 12 Nov 2002
    4.6
    Medium

    CVE-2002-1184

    Last Modified: 16 Apr 2026

    The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.

    Published: 12 Nov 2002
    7.2
    High

    CVE-2002-1245

    Last Modified: 16 Apr 2026

    Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program.

    Published: 12 Nov 2002
    5
    Medium

    CVE-2002-1265

    Last Modified: 16 Apr 2026

    The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1271

    Last Modified: 16 Apr 2026

    The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the mail body, which is then processed by mailx.

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1278

    Last Modified: 16 Apr 2026

    The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail relay, which allows remote attackers to send Spam email.

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1180

    Last Modified: 16 Apr 2026

    A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1211

    Last Modified: 16 Apr 2026

    Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.

    Published: 12 Nov 2002
    5
    Medium

    CVE-2002-1236

    Last Modified: 16 Apr 2026

    The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.

    Published: 12 Nov 2002
    5
    Medium

    CVE-2002-1248

    Last Modified: 16 Apr 2026

    Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) via a GET request for a "%" URI.

    Published: 12 Nov 2002
    7.2
    High

    CVE-2002-1250

    Last Modified: 16 Apr 2026

    Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument.

    Published: 12 Nov 2002
    10
    Critical

    CVE-2002-1251

    Last Modified: 16 Apr 2026

    Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message.

    Published: 12 Nov 2002
    5
    Medium

    CVE-2002-1182

    Last Modified: 16 Apr 2026

    IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.

    Published: 12 Nov 2002
    7.2
    High

    CVE-2002-1239

    Last Modified: 16 Apr 2026

    QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1242

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1244

    Last Modified: 16 Apr 2026

    Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-0029

    Last Modified: 16 Apr 2026

    Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1306

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan://" URL.

    Published: 12 Nov 2002
    7.5
    High

    CVE-2002-1282

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL.

    Published: 11 Nov 2002
    7.2
    High

    CVE-2002-1247

    Last Modified: 16 Apr 2026

    Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon.

    Published: 11 Nov 2002
    2.1
    Low

    CVE-2002-1319

    Last Modified: 16 Apr 2026

    The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.

    Published: 11 Nov 2002
    7.5
    High

    CVE-2002-1281

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote attackers to execute arbitrary code via a certain URL.

    Published: 11 Nov 2002
    5
    Medium

    CVE-2002-0711

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.

    Published: 10 Nov 2002
    7.5
    High

    CVE-2002-1238

    Last Modified: 16 Apr 2026

    Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.

    Published: 10 Nov 2002
    7.5
    High

    CVE-2002-1275

    Last Modified: 16 Apr 2026

    Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."

    Published: 10 Nov 2002
    5
    Medium

    CVE-2002-1585

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Solaris 8 for Intel and Solaris 8 and 9 for SPARC allows remote attackers to cause a denial of service via certain packets that cause some network interfaces to stop responding to TCP traffic.

    Published: 8 Nov 2002
    5
    Medium

    CVE-2002-1320

    Last Modified: 16 Apr 2026

    Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").

    Published: 7 Nov 2002
    7.5
    High

    CVE-2002-1277

    Last Modified: 16 Apr 2026

    Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer.

    Published: 7 Nov 2002
    4.6
    Medium

    CVE-2002-1230

    Last Modified: 16 Apr 2026

    NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation."

    Published: 4 Nov 2002
    2.1
    Low

    CVE-2002-1231

    Last Modified: 16 Apr 2026

    SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc.

    Published: 4 Nov 2002
    5
    Medium

    CVE-2002-1169

    Last Modified: 16 Apr 2026

    IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.

    Published: 4 Nov 2002
    5
    Medium

    CVE-2002-1362

    Last Modified: 16 Apr 2026

    mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.

    Published: 3 Nov 2002
    7.5
    High

    CVE-2002-0869

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."

    Published: 2 Nov 2002
    6.8
    Medium

    CVE-2002-1181

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.

    Published: 2 Nov 2002
    4.3
    Medium

    CVE-2002-1276

    Last Modified: 16 Apr 2026

    An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.

    Published: 2 Nov 2002
    1.2
    Low

    CVE-2002-1563

    Last Modified: 16 Apr 2026

    stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions that cause an inconsistency in the child counter.

    Published: 30 Oct 2002
    7.2
    High

    CVE-2002-1590

    Last Modified: 16 Apr 2026

    The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.

    Published: 29 Oct 2002
    5
    Medium

    CVE-2002-1209

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.

    Published: 29 Oct 2002
    5
    Medium

    CVE-2002-0386

    Last Modified: 16 Apr 2026

    The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data.

    Published: 29 Oct 2002
    4.3
    Medium

    CVE-2002-1195

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability (XSS) in the PHP interface for ht://Check 1.1 allows remote web servers to insert arbitrary HTML, including script, via a web page.

    Published: 28 Oct 2002
    7.5
    High

    CVE-2002-1196

    Last Modified: 16 Apr 2026

    editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.

    Published: 28 Oct 2002
    7.5
    High

    CVE-2002-1197

    Last Modified: 16 Apr 2026

    bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.

    Published: 28 Oct 2002
    7.5
    High

    CVE-2002-1200

    Last Modified: 16 Apr 2026

    Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.

    Published: 28 Oct 2002
    5
    Medium

    CVE-2002-0990

    Last Modified: 16 Apr 2026

    The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple connection requests to domains whose DNS server is unresponsive or does not exist, which generates a long timeout.

    Published: 28 Oct 2002
    7.5
    High

    CVE-2002-1179

    Last Modified: 16 Apr 2026

    Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.

    Published: 28 Oct 2002
    7.5
    High

    CVE-2002-1198

    Last Modified: 16 Apr 2026

    Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.

    Published: 28 Oct 2002