CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2002-1222

    Last Modified: 16 Apr 2026

    Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

    Published: 28 Oct 2002
    5
    Medium

    CVE-2002-1118

    Last Modified: 16 Apr 2026

    TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.

    Published: 28 Oct 2002
    2.1
    Low

    CVE-2002-1193

    Last Modified: 16 Apr 2026

    tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.

    Published: 28 Oct 2002
    7.5
    High

    CVE-2002-1227

    Last Modified: 16 Apr 2026

    PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.

    Published: 28 Oct 2002
    2.1
    Low

    CVE-2002-1395

    Last Modified: 16 Apr 2026

    Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz.

    Published: 28 Oct 2002
    5
    Medium

    CVE-2002-0666

    Last Modified: 16 Apr 2026

    IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.

    Published: 25 Oct 2002
    6.8
    Medium

    CVE-2002-1167

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

    Published: 25 Oct 2002
    6.8
    Medium

    CVE-2002-1168

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

    Published: 25 Oct 2002
    2.6
    Low

    CVE-2002-1233

    Last Modified: 16 Apr 2026

    A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.

    Published: 25 Oct 2002
    Unknown

    CVE-2002-1234

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0180. Reason: This candidate is a an out-of-band assignment duplicate of CVE-2002-0180. Notes: All CVE users should reference CVE-2002-0180 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Oct 2002
    2.1
    Low

    CVE-2002-1589

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of service (system panic).

    Published: 24 Oct 2002
    10
    Critical

    CVE-2002-1235

    Last Modified: 16 Apr 2026

    The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

    Published: 23 Oct 2002
    5
    Medium

    CVE-2001-1451

    Last Modified: 16 Apr 2026

    Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.

    Published: 22 Oct 2002
    7.5
    High

    CVE-2002-1157

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.

    Published: 22 Oct 2002
    7.5
    High

    CVE-2002-1217

    Last Modified: 16 Apr 2026

    Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.

    Published: 21 Oct 2002
    5
    Medium

    CVE-2002-1212

    Last Modified: 16 Apr 2026

    Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

    Published: 21 Oct 2002
    5
    Medium

    CVE-2002-1213

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters.

    Published: 21 Oct 2002
    10
    Critical

    CVE-2002-1215

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 694 (incorrectly claimed as TCP in some sources).

    Published: 21 Oct 2002
    10
    Critical

    CVE-2002-1145

    Last Modified: 16 Apr 2026

    The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.

    Published: 21 Oct 2002
    5
    Medium

    CVE-2002-1191

    Last Modified: 16 Apr 2026

    The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.

    Published: 21 Oct 2002
    10
    Critical

    CVE-2002-1225

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.

    Published: 21 Oct 2002
    10
    Critical

    CVE-2002-1226

    Last Modified: 16 Apr 2026

    Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).

    Published: 21 Oct 2002
    5
    Medium

    CVE-2002-1228

    Last Modified: 16 Apr 2026

    Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.

    Published: 21 Oct 2002
    7.5
    High

    CVE-2002-1229

    Last Modified: 16 Apr 2026

    Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.

    Published: 21 Oct 2002
    5
    Medium

    CVE-2002-1232

    Last Modified: 16 Apr 2026

    Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.

    Published: 21 Oct 2002
    7.2
    High

    CVE-2002-1618

    Last Modified: 16 Apr 2026

    JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.

    Published: 16 Oct 2002
    Unknown

    CVE-2002-0646

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0371. Reason: This candidate is a reservation duplicate of CVE-2002-0371. Notes: CVE-2002-0371 should be used instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Oct 2002
    7.5
    High

    CVE-2002-1190

    Last Modified: 16 Apr 2026

    Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.

    Published: 15 Oct 2002
    5
    Medium

    CVE-2002-1201

    Last Modified: 16 Apr 2026

    IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.

    Published: 15 Oct 2002
    7.5
    High

    CVE-2002-1202

    Last Modified: 16 Apr 2026

    Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.

    Published: 15 Oct 2002
    5
    Medium

    CVE-2002-1203

    Last Modified: 16 Apr 2026

    IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.

    Published: 15 Oct 2002
    4.6
    Medium

    CVE-2002-1192

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.

    Published: 15 Oct 2002
    7.5
    High

    CVE-2002-1194

    Last Modified: 16 Apr 2026

    Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.

    Published: 15 Oct 2002
    7.5
    High

    CVE-2002-0836

    Last Modified: 16 Apr 2026

    dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.

    Published: 14 Oct 2002
    5
    Medium

    CVE-2002-0864

    Last Modified: 16 Apr 2026

    The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop."

    Published: 11 Oct 2002
    5
    Medium

    CVE-2002-1141

    Last Modified: 16 Apr 2026

    An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."

    Published: 11 Oct 2002
    7.5
    High

    CVE-2002-0865

    Last Modified: 16 Apr 2026

    A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet, aka "Inappropriate Methods Exposed in XML Support Classes."

    Published: 11 Oct 2002
    7.8
    High

    CVE-2002-0969

    Last Modified: 16 Apr 2026

    Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.

    Published: 11 Oct 2002
    7.5
    High

    CVE-2002-1137

    Last Modified: 16 Apr 2026

    Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.

    Published: 11 Oct 2002
    5
    Medium

    CVE-2002-1139

    Last Modified: 16 Apr 2026

    The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a user's system, aka "Incorrect Target Path for Zipped File Decompression."

    Published: 11 Oct 2002
    7.1
    High

    CVE-2002-1147

    Last Modified: 16 Apr 2026

    The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program.

    Published: 11 Oct 2002
    7.5
    High

    CVE-2002-0866

    Last Modified: 16 Apr 2026

    Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka "DLL Execution via JDBC Classes."

    Published: 11 Oct 2002
    5
    Medium

    CVE-2002-0867

    Last Modified: 16 Apr 2026

    Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw."

    Published: 11 Oct 2002
    7.5
    High

    CVE-2002-1138

    Last Modified: 16 Apr 2026

    Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."

    Published: 11 Oct 2002
    5
    Medium

    CVE-2002-1153

    Last Modified: 16 Apr 2026

    IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".

    Published: 11 Oct 2002
    5
    Medium

    CVE-2002-1156

    Last Modified: 16 Apr 2026

    Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.

    Published: 11 Oct 2002
    5
    Medium

    CVE-2002-1178

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.

    Published: 11 Oct 2002
    4.6
    Medium

    CVE-2002-1189

    Last Modified: 16 Apr 2026

    The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.

    Published: 11 Oct 2002
    5
    Medium

    CVE-2002-1140

    Last Modified: 16 Apr 2026

    The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."

    Published: 11 Oct 2002
    5
    Medium

    CVE-2002-1511

    Last Modified: 16 Apr 2026

    The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.

    Published: 11 Oct 2002