CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2002-0905

    Last Modified: 16 Apr 2026

    Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0907

    Last Modified: 16 Apr 2026

    Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-".

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0908

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTPS request.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0912

    Last Modified: 16 Apr 2026

    in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote attackers to cause a denial of service, possibly due to a buffer overflow.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0913

    Last Modified: 16 Apr 2026

    Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response.

    Published: 31 Aug 2002
    2.1
    Low

    CVE-2002-0915

    Last Modified: 16 Apr 2026

    autorun in Xandros based Linux distributions allows local users to read the first line of arbitrary files via the -c parameter, which causes autorun to print the first line of the file.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0922

    Last Modified: 16 Apr 2026

    CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0923

    Last Modified: 16 Apr 2026

    CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0924

    Last Modified: 16 Apr 2026

    CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0936

    Last Modified: 16 Apr 2026

    The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-0937

    Last Modified: 16 Apr 2026

    The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).

    Published: 31 Aug 2002
    10
    Critical

    CVE-2002-0951

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0954

    Last Modified: 16 Apr 2026

    The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make it easier for an attacker to decrypt the passwords using brute force techniques.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0955

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site visitors via script in the num parameter, which is not filtered in the resulting error message.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0950

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0960

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allows remote attackers to execute arbitrary script as other CBMS users.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-0961

    Last Modified: 16 Apr 2026

    Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other users, e.g. by deleting clients via dltclnt.php, possibly in a SQL injection attack.

    Published: 31 Aug 2002
    7.2
    High

    CVE-2002-0991

    Last Modified: 16 Apr 2026

    Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters.

    Published: 31 Aug 2002
    2.1
    Low

    CVE-2002-0992

    Last Modified: 16 Apr 2026

    Unknown vulnerability in IPV6 functionality for DCE daemons (1) dced or (2) rpcd on HP-UX 11.11 allows attackers to cause a denial of service (crash) via an attack that modifies internal data.

    Published: 31 Aug 2002
    4.6
    Medium

    CVE-2002-0993

    Last Modified: 16 Apr 2026

    Unknown vulnerability in HP Instant Support Enterprise Edition (ISEE) product U2512A for HP-UX 11.00 and 11.11 may allow authenticated users to access restricted files.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1003

    Last Modified: 16 Apr 2026

    Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1005

    Last Modified: 16 Apr 2026

    ArGoSoft Mail Server 1.8.1.7 and earlier allows a webmail user to cause a denial of service (CPU consumption) by forwarding the email to the user while autoresponse is enabled, which creates an infinite loop.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1010

    Last Modified: 16 Apr 2026

    Lotus Domino R4 allows remote attackers to bypass access restrictions for files in the web root via an HTTP request appended with a "?" character, which is treated as a wildcard character and bypasses the web handlers.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1011

    Last Modified: 16 Apr 2026

    Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1012

    Last Modified: 16 Apr 2026

    Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1020

    Last Modified: 16 Apr 2026

    The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook even when the maximum number of loans is exceeded by accessing the "Add to bookbag" feature when the server reports that no more copies are available.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1021

    Last Modified: 16 Apr 2026

    BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1022

    Last Modified: 16 Apr 2026

    BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1027

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1028

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash) via long arguments.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1029

    Last Modified: 16 Apr 2026

    Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to TCP port 17990.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1032

    Last Modified: 16 Apr 2026

    Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1040

    Last Modified: 16 Apr 2026

    Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1041

    Last Modified: 16 Apr 2026

    Unknown vulnerability in DCE (1) SMIT panels and (2) configuration commands, possibly related to relative pathnames.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1047

    Last Modified: 16 Apr 2026

    The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1048

    Last Modified: 16 Apr 2026

    HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1061

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP GET request with a long major version number, (2) an HTTP GET request to the HTTP proxy on port 3128 with a long major version number, (3) a long OK reply from a POP3 server, and (4) a long SMTP server response.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1062

    Last Modified: 16 Apr 2026

    Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1063

    Last Modified: 16 Apr 2026

    Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV requests, which consumes all available FTP ports.

    Published: 31 Aug 2002
    10
    Critical

    CVE-2002-1058

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1071

    Last Modified: 16 Apr 2026

    ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1072

    Last Modified: 16 Apr 2026

    ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1073

    Last Modified: 16 Apr 2026

    Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1075

    Last Modified: 16 Apr 2026

    Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.

    Published: 31 Aug 2002
    5
    Medium

    CVE-2002-1082

    Last Modified: 16 Apr 2026

    The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.

    Published: 31 Aug 2002
    6.4
    Medium

    CVE-2002-1084

    Last Modified: 16 Apr 2026

    The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1085

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.

    Published: 31 Aug 2002
    7.5
    High

    CVE-2002-1086

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.

    Published: 31 Aug 2002
    4.6
    Medium

    CVE-2002-1607

    Last Modified: 16 Apr 2026

    Buffer overflow in ypmatch in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to execute arbitrary code.

    Published: 31 Aug 2002
    4.6
    Medium

    CVE-2002-1608

    Last Modified: 16 Apr 2026

    Buffer overflow in traceroute in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to execute arbitrary code.

    Published: 31 Aug 2002