CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2002-0399

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.

    Published: 30 Sept 2002
    5
    Medium

    CVE-2002-1175

    Last Modified: 16 Apr 2026

    The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.

    Published: 29 Sept 2002
    7.5
    High

    CVE-2002-1174

    Last Modified: 16 Apr 2026

    Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function.

    Published: 29 Sept 2002
    5
    Medium

    CVE-2002-1216

    Last Modified: 16 Apr 2026

    GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.

    Published: 28 Sept 2002
    4.6
    Medium

    CVE-2002-0838

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf.

    Published: 26 Sept 2002
    5
    Medium

    CVE-2002-1593

    Last Modified: 16 Apr 2026

    mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.

    Published: 25 Sept 2002
    5
    Medium

    CVE-2002-0648

    Last Modified: 16 Apr 2026

    The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.

    Published: 24 Sept 2002
    7.2
    High

    CVE-2002-0987

    Last Modified: 16 Apr 2026

    X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-1122

    Last Modified: 16 Apr 2026

    Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers to execute arbitrary code via a long web server response.

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-0726

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to execute arbitrary code via a long server name field.

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-0727

    Last Modified: 16 Apr 2026

    The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

    Published: 24 Sept 2002
    10
    Critical

    CVE-2002-0988

    Last Modified: 16 Apr 2026

    Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities.

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-1123

    Last Modified: 16 Apr 2026

    Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.

    Published: 24 Sept 2002
    5
    Medium

    CVE-2002-1133

    Last Modified: 16 Apr 2026

    Encoded directory traversal vulnerability in Dino's web server 2.1 allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "\" (%5c) characters.

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-0376

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrary code via a long pluginspage field.

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-0722

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."

    Published: 24 Sept 2002
    5
    Medium

    CVE-2002-0860

    Last Modified: 16 Apr 2026

    The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.

    Published: 24 Sept 2002
    7.2
    High

    CVE-2002-1129

    Last Modified: 16 Apr 2026

    Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.

    Published: 24 Sept 2002
    5
    Medium

    CVE-2002-0974

    Last Modified: 16 Apr 2026

    Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm.

    Published: 24 Sept 2002
    7.2
    High

    CVE-2002-0981

    Last Modified: 16 Apr 2026

    Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line.

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-0984

    Last Modified: 16 Apr 2026

    The IRC script included in Light 2.7.x before 2.7.30p5, and 2.8.x before 2.8pre10, running EPIC allows remote attackers to execute arbitrary code if the user joins a channel whose topic includes EPIC4 code.

    Published: 24 Sept 2002
    7.2
    High

    CVE-2002-1127

    Last Modified: 16 Apr 2026

    Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.

    Published: 24 Sept 2002
    7.2
    High

    CVE-2002-1128

    Last Modified: 16 Apr 2026

    Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.

    Published: 24 Sept 2002
    5
    Medium

    CVE-2002-1134

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Compaq WEBES Service Tools 2.0 through WEBES 4.0 (Service Pack 5) allows local users to read privileged files.

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-0647

    Last Modified: 16 Apr 2026

    Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".

    Published: 24 Sept 2002
    7.5
    High

    CVE-2002-0691

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.01 and 5.5 allows remote attackers to execute scripts in the Local Computer zone via a URL that references a local HTML resource file, a variant of "Cross-Site Scripting in Local HTML Resource" as identified by CAN-2002-0189.

    Published: 24 Sept 2002
    5
    Medium

    CVE-2002-1148

    Last Modified: 16 Apr 2026

    The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

    Published: 24 Sept 2002
    7.2
    High

    CVE-2002-1472

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.

    Published: 18 Sept 2002
    7.2
    High

    CVE-2002-1124

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in purity 1-16 allow local users to gain privileges and modify high scores tables.

    Published: 17 Sept 2002
    2.1
    Low

    CVE-2002-1125

    Last Modified: 16 Apr 2026

    FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory.

    Published: 17 Sept 2002
    7.5
    High

    CVE-2002-1131

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.

    Published: 16 Sept 2002
    5
    Medium

    CVE-2002-1132

    Last Modified: 16 Apr 2026

    SquirrelMail 1.2.7 and earlier allows remote attackers to determine the absolute pathname of the options.php script via a malformed optpage file argument, which generates an error message when the file cannot be included in the script.

    Published: 16 Sept 2002
    7.5
    High

    CVE-2002-1121

    Last Modified: 16 Apr 2026

    SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type.

    Published: 14 Sept 2002
    7.2
    High

    CVE-2002-1615

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader.

    Published: 13 Sept 2002
    7.2
    High

    CVE-2002-1612

    Last Modified: 16 Apr 2026

    Buffer overflow in mailcv in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.

    Published: 13 Sept 2002
    7.5
    High

    CVE-2002-1120

    Last Modified: 16 Apr 2026

    Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 12 Sept 2002
    7.5
    High

    CVE-2002-0664

    Last Modified: 16 Apr 2026

    The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to read or modify import/export scripts.

    Published: 10 Sept 2002
    5
    Medium

    CVE-2002-1115

    Last Modified: 16 Apr 2026

    Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php.

    Published: 10 Sept 2002
    6.8
    Medium

    CVE-2002-0862

    Last Modified: 16 Apr 2026

    The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

    Published: 10 Sept 2002
    5
    Medium

    CVE-2002-1100

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.

    Published: 10 Sept 2002
    10
    Critical

    CVE-2002-1110

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php.

    Published: 10 Sept 2002
    7.5
    High

    CVE-2002-1114

    Last Modified: 16 Apr 2026

    config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_include_page, (2) g_top_include_page, (3) g_css_include_file, (4) g_meta_include_file, or (5) a cookie.

    Published: 10 Sept 2002
    5
    Medium

    CVE-2002-1094

    Last Modified: 16 Apr 2026

    Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.

    Published: 10 Sept 2002
    5
    Medium

    CVE-2002-1101

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

    Published: 10 Sept 2002
    5
    Medium

    CVE-2002-1103

    Last Modified: 16 Apr 2026

    Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.

    Published: 10 Sept 2002
    7.2
    High

    CVE-2002-1613

    Last Modified: 16 Apr 2026

    Buffer overflow in ps in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.

    Published: 10 Sept 2002
    7.5
    High

    CVE-2002-1152

    Last Modified: 16 Apr 2026

    Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing.

    Published: 10 Sept 2002
    7.2
    High

    CVE-2002-1614

    Last Modified: 16 Apr 2026

    Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.

    Published: 9 Sept 2002
    7.5
    High

    CVE-2002-0837

    Last Modified: 16 Apr 2026

    wordtrans 1.1pre8 and earlier in the wordtrans-web package allows remote attackers to (1) execute arbitrary code or (2) conduct cross-site scripting attacks via certain parameters (possibly "dict") to the wordtrans.php script.

    Published: 9 Sept 2002
    5
    Medium

    CVE-2002-2215

    Last Modified: 16 Apr 2026

    The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which triggers an error in the rfc822_write_address function.

    Published: 7 Sept 2002