CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-0692

    Last Modified: 16 Apr 2026

    Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.

    Published: 10 Oct 2002
    7.5
    High

    CVE-2002-0694

    Last Modified: 16 Apr 2026

    The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."

    Published: 10 Oct 2002
    7.5
    High

    CVE-2002-1394

    Last Modified: 16 Apr 2026

    Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.

    Published: 9 Oct 2002
    7.5
    High

    CVE-2002-1223

    Last Modified: 16 Apr 2026

    Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a denial of service or execute arbitrary code via a modified .ps (PostScript) input file.

    Published: 8 Oct 2002
    5
    Medium

    CVE-2002-1224

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.

    Published: 8 Oct 2002
    3.6
    Low

    CVE-2002-1509

    Last Modified: 16 Apr 2026

    A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users in the same group to read or modify the new user's incoming email.

    Published: 8 Oct 2002
    7.5
    High

    CVE-2002-0693

    Last Modified: 16 Apr 2026

    Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.

    Published: 5 Oct 2002
    7.5
    High

    CVE-2002-0370

    Last Modified: 16 Apr 2026

    Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

    Published: 5 Oct 2002
    7.5
    High

    CVE-2002-0696

    Last Modified: 16 Apr 2026

    Microsoft Visual FoxPro 6.0 does not register its associated files with Internet Explorer, which allows remote attackers to execute Visual FoxPro applications without warning via HTML that references specially-crafted filenames.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0916

    Last Modified: 16 Apr 2026

    Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0958

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in browse.php for PHP(Reactor) 1.2.7 allows remote attackers to execute script as other users via the go parameter in the comments section.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0967

    Last Modified: 16 Apr 2026

    Buffer overflow in eDonkey 2000 35.16.60 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long "ed2k:" URL.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1081

    Last Modified: 16 Apr 2026

    The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1099

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0904

    Last Modified: 16 Apr 2026

    SayText function in Kismet 2.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters (backtick or pipe) in the essid argument.

    Published: 4 Oct 2002
    7.2
    High

    CVE-2002-0911

    Last Modified: 16 Apr 2026

    Caldera Volution Manager 1.1 stores the Directory Administrator password in cleartext in the slapd.conf file, which could allow local users to gain privileges.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-0914

    Last Modified: 16 Apr 2026

    Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop.

    Published: 4 Oct 2002
    4.6
    Medium

    CVE-2002-0941

    Last Modified: 16 Apr 2026

    The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-0964

    Last Modified: 16 Apr 2026

    Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial challenge with different cd_key values, which reaches the player limit and prevents other players from connecting until the original responses have timed out.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0968

    Last Modified: 16 Apr 2026

    Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1025

    Last Modified: 16 Apr 2026

    JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP file unparsed.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1039

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to read arbitrary files via .. (dot dot) sequences when downloading files from the Projects: Attachments feature.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1049

    Last Modified: 16 Apr 2026

    Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1057

    Last Modified: 16 Apr 2026

    Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1092

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1098

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1107

    Last Modified: 16 Apr 2026

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1050

    Last Modified: 16 Apr 2026

    Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0850

    Last Modified: 16 Apr 2026

    Buffer overflow in PGP Corporate Desktop 7.1.1 allows remote attackers to execute arbitrary code via an encrypted document that has a long filename when it is decrypted.

    Published: 4 Oct 2002
    2.1
    Low

    CVE-2002-0887

    Last Modified: 16 Apr 2026

    scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.

    Published: 4 Oct 2002
    4.6
    Medium

    CVE-2002-0889

    Last Modified: 16 Apr 2026

    Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a long bulldir argument in the user's .qpopper-options configuration file.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-0891

    Last Modified: 16 Apr 2026

    The web interface (WebUI) of NetScreen ScreenOS before 2.6.1r8, and certain 2.8.x and 3.0.x versions before 3.0.3r1, allows remote attackers to cause a denial of service (crash) via a long user name.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-0892

    Last Modified: 16 Apr 2026

    The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0895

    Last Modified: 16 Apr 2026

    Buffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PASS (password) command.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0897

    Last Modified: 16 Apr 2026

    LocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that contains the "/./" directory.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-0898

    Last Modified: 16 Apr 2026

    Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input type=file tag whose value contains a newline.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0900

    Last Modified: 16 Apr 2026

    Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long search argument to the lookup capability.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0906

    Last Modified: 16 Apr 2026

    Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-0935

    Last Modified: 16 Apr 2026

    Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0938

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0945

    Last Modified: 16 Apr 2026

    Buffer overflow in SeaNox Devwex allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-0946

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files via ..\ (dot dot) sequences in an HTTP request.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0947

    Last Modified: 16 Apr 2026

    Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-0952

    Last Modified: 16 Apr 2026

    Cisco ONS15454 optical transport platform running ONS 3.1.0 to 3.2.0 allows remote attackers to cause a denial of service (reset) by sending IP packets with non-zero Type of Service (TOS) bits to the Timing Control Card (TCC) LAN interface.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0953

    Last Modified: 16 Apr 2026

    globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to execute arbitrary PHP code via a URL to the code in the LangCookie parameter.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1002

    Last Modified: 16 Apr 2026

    Buffer overflow in Novell iManager (eMFrame 1.2.1) allows remote attackers to cause a denial of service (crash) via a long user name.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1004

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.

    Published: 4 Oct 2002
    6.8
    Medium

    CVE-2002-1006

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1000

    Last Modified: 16 Apr 2026

    Buffer overflow in AnalogX SimpleServer:Shout 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long request to TCP port 8001.

    Published: 4 Oct 2002
    7.2
    High

    CVE-2002-1013

    Last Modified: 16 Apr 2026

    Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Media-IXT 3.0.4 allows local users to gain root privileges via a long -path argument.

    Published: 4 Oct 2002