CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-1014

    Last Modified: 16 Apr 2026

    Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image.

    Published: 4 Oct 2002
    2.6
    Low

    CVE-2002-1030

    Last Modified: 16 Apr 2026

    Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1031

    Last Modified: 16 Apr 2026

    KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1046

    Last Modified: 16 Apr 2026

    Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to TCP port 4110.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1059

    Last Modified: 16 Apr 2026

    Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string.

    Published: 4 Oct 2002
    4.3
    Medium

    CVE-2002-1060

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted into the resulting error page.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1076

    Last Modified: 16 Apr 2026

    Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1088

    Last Modified: 16 Apr 2026

    Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1093

    Last Modified: 16 Apr 2026

    HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1095

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1096

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1097

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1102

    Last Modified: 16 Apr 2026

    The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1104

    Last Modified: 16 Apr 2026

    Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).

    Published: 4 Oct 2002
    4.6
    Medium

    CVE-2002-1105

    Last Modified: 16 Apr 2026

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1111

    Last Modified: 16 Apr 2026

    print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries for bugs that would otherwise be restricted.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1112

    Last Modified: 16 Apr 2026

    Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1113

    Last Modified: 16 Apr 2026

    summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1108

    Last Modified: 16 Apr 2026

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.

    Published: 4 Oct 2002
    2.1
    Low

    CVE-2002-1109

    Last Modified: 16 Apr 2026

    securetar, as used in AMaViS shell script 0.2.1 and earlier, allows users to cause a denial of service (CPU consumption) via a malformed TAR file, possibly via an incorrect file size parameter.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1135

    Last Modified: 16 Apr 2026

    modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0965

    Last Modified: 16 Apr 2026

    Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-0995

    Last Modified: 16 Apr 2026

    login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1015

    Last Modified: 16 Apr 2026

    RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.

    Published: 4 Oct 2002
    7.1
    High

    CVE-2002-1024

    Last Modified: 16 Apr 2026

    Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1035

    Last Modified: 16 Apr 2026

    Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number.

    Published: 4 Oct 2002
    4.6
    Medium

    CVE-2002-1051

    Last Modified: 16 Apr 2026

    Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.

    Published: 4 Oct 2002
    6.8
    Medium

    CVE-2002-1053

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error message.

    Published: 4 Oct 2002
    6.4
    Medium

    CVE-2002-1054

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Pablo FTP server 1.0 build 9 and earlier allows remote authenticated users to list arbitrary directories via "..\" (dot-dot backslash) sequences in a LIST command.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1079

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1106

    Last Modified: 16 Apr 2026

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks.

    Published: 4 Oct 2002
    7.5
    High

    CVE-2002-1116

    Last Modified: 16 Apr 2026

    The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have access to any projects.

    Published: 4 Oct 2002
    5
    Medium

    CVE-2002-1117

    Last Modified: 16 Apr 2026

    Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.

    Published: 4 Oct 2002
    4.6
    Medium

    CVE-2002-1323

    Last Modified: 16 Apr 2026

    Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.

    Published: 4 Oct 2002
    7.2
    High

    CVE-2002-1642

    Last Modified: 16 Apr 2026

    PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command.

    Published: 3 Oct 2002
    7.5
    High

    CVE-2002-0705

    Last Modified: 16 Apr 2026

    The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.

    Published: 3 Oct 2002
    7.5
    High

    CVE-2002-0706

    Last Modified: 16 Apr 2026

    UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.

    Published: 3 Oct 2002
    5
    Medium

    CVE-2002-0707

    Last Modified: 16 Apr 2026

    The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.

    Published: 3 Oct 2002
    5
    Medium

    CVE-2002-0708

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.

    Published: 3 Oct 2002
    7.5
    High

    CVE-2002-0709

    Last Modified: 16 Apr 2026

    SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.

    Published: 3 Oct 2002
    7.2
    High

    CVE-2002-0839

    Last Modified: 16 Apr 2026

    The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.

    Published: 3 Oct 2002
    5
    Medium

    CVE-2002-1146

    Last Modified: 16 Apr 2026

    The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).

    Published: 3 Oct 2002
    7.5
    High

    CVE-2002-0843

    Last Modified: 16 Apr 2026

    Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.

    Published: 3 Oct 2002
    6.8
    Medium

    CVE-2002-0840

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

    Published: 2 Oct 2002
    5
    Medium

    CVE-2002-1170

    Last Modified: 16 Apr 2026

    The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.

    Published: 2 Oct 2002
    7.5
    High

    CVE-2002-1166

    Last Modified: 16 Apr 2026

    Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request.

    Published: 1 Oct 2002
    5
    Medium

    CVE-2002-0863

    Last Modified: 16 Apr 2026

    Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."

    Published: 1 Oct 2002
    4.6
    Medium

    CVE-2002-1150

    Last Modified: 16 Apr 2026

    The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and canceling out of the resulting user confirmation prompts, such as when the remote user is editing a document.

    Published: 1 Oct 2002
    5
    Medium

    CVE-2002-1149

    Last Modified: 16 Apr 2026

    The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings.

    Published: 1 Oct 2002
    4.6
    Medium

    CVE-2002-1165

    Last Modified: 16 Apr 2026

    Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

    Published: 1 Oct 2002