CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2002-1001

    Last Modified: 16 Apr 2026

    Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1018

    Last Modified: 16 Apr 2026

    The library feature for Adobe Content Server 3.0 does not verify if a customer has already checked out an eBook, which allows remote attackers to cause a denial of service (resource exhaustion) by checking out the same book multiple times.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1036

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1043

    Last Modified: 16 Apr 2026

    Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1069

    Last Modified: 16 Apr 2026

    The remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP addresses or obtain sensitive information via a direct web request to the pages (1) release.htm, (2) Device Status, or (3) Device Information.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0699

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0876

    Last Modified: 16 Apr 2026

    Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0877

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the FTP server for Shambala 4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) LIST (ls) or (2) GET commands.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0878

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0885

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0886

    Last Modified: 16 Apr 2026

    Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0918

    Last Modified: 16 Apr 2026

    CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter, which generates an error.

    Published: 31 Aug 2002
    5.1
    Medium

    CVE-2002-0920

    Last Modified: 16 Apr 2026

    CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0921

    Last Modified: 16 Apr 2026

    CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other configuration settings, via the viewnews command with an invalid database, which leaks the information in error messages.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0931

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" parameter to the index.php script with the (3) tickettime, (4) ticketfiles, or (5) updateticketlog operations, or (6) via the update section when a ticket is edited.

    Published: 31 Aug 2002
    6.4
    Medium

    CVE-2002-0934

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.

    Published: 31 Aug 2002
    4.6
    Medium

    CVE-2002-0940

    Last Modified: 16 Apr 2026

    domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).

    Published: 31 Aug 2002
    6.4
    Medium

    CVE-2002-0943

    Last Modified: 16 Apr 2026

    MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0944

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0949

    Last Modified: 16 Apr 2026

    Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a reply that includes the router's password and other sensitive information in cleartext.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0959

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0963

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in comment.php for GeekLog 1.3.5 and earlier allows remote attackers to obtain sensitive user information via the pid parameter.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0998

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in cafenews.php for CARE 2002 before beta 1.0.02 allows remote attackers to read arbitrary files via .. (dot dot) sequences and null characters in the lang parameter, which is processed by a call to the include function.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1007

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1008

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1009

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.

    Published: 31 Aug 2002
    4.6
    Medium

    CVE-2002-1016

    Last Modified: 16 Apr 2026

    Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files, performing the operations, and restoring the original data files.

    Published: 31 Aug 2002
    2.1
    Low

    CVE-2002-1017

    Last Modified: 16 Apr 2026

    Adobe eBook Reader 2.1 and 2.2 allows a user to copy eBooks to other systems by using the backup feature, capturing the encryption Challenge, and using the appropriate hash function to generate the activation code.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1019

    Last Modified: 16 Apr 2026

    The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook for an arbitrary length of time via a modified loanMin parameter to download.asp.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1026

    Last Modified: 16 Apr 2026

    Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long malformed request to TCP port 2500, possibly triggering a buffer overflow.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1037

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1038

    Last Modified: 16 Apr 2026

    Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1042

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1044

    Last Modified: 16 Apr 2026

    Buffer overflow in Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Subject field.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1064

    Last Modified: 16 Apr 2026

    Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1066

    Last Modified: 16 Apr 2026

    Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command to the POP3 server, which exceeds the array limits and allows a buffer overflow attack.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1067

    Last Modified: 16 Apr 2026

    Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buffer overflow.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1068

    Last Modified: 16 Apr 2026

    The web server for D-Link DP-300 print server allows remote attackers to cause a denial of service (hang) via a large HTTP POST request.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1070

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1083

    Last Modified: 16 Apr 2026

    Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot) sequences.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1087

    Last Modified: 16 Apr 2026

    The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1089

    Last Modified: 16 Apr 2026

    rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1045

    Last Modified: 16 Apr 2026

    Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Date field that is converted into a year greater than 2037.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1023

    Last Modified: 16 Apr 2026

    BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0879

    Last Modified: 16 Apr 2026

    showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.

    Published: 31 Aug 2002
    2.1
    Low

    CVE-2002-0881

    Last Modified: 16 Apr 2026

    Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0888

    Last Modified: 16 Apr 2026

    3Com OfficeConnect Remote 812 ADSL Router, firmware 1.1.9 and 1.1.7, allows remote attackers to bypass port access restrictions by connecting to an approved port and quickly connecting to the desired port, which is allowed by the router.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0899

    Last Modified: 16 Apr 2026

    Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot).

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0917

    Last Modified: 16 Apr 2026

    CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0896

    Last Modified: 16 Apr 2026

    The throttle capability in Swatch may fail to report certain events if (1) the same type of event occurs after the throttle period, or (2) when multiple events matching the same "watchfor" expression do not occur after the throttle period, which could allow attackers to avoid detection.

    Published: 31 Aug 2002