CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2002-0997

    Last Modified: 16 Apr 2026

    Buffer overflows in IMAP Agent (imapd) for Novell NetMail (NIMS) 3.0.3 before 3.0.3A allows remote attackers to cause a denial of service.

    Published: 31 Aug 2002
    4.6
    Medium

    CVE-2002-1606

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain privileges via (1) lpc, (2) lpd, (3) lpq, (4) lpr, or (5) lprm.

    Published: 30 Aug 2002
    4.6
    Medium

    CVE-2002-1611

    Last Modified: 16 Apr 2026

    Buffer overflow in quot in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.

    Published: 30 Aug 2002
    2.1
    Low

    CVE-2002-1610

    Last Modified: 16 Apr 2026

    Unknown vulnerability in ping in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to cause a denial of service.

    Published: 30 Aug 2002
    4.6
    Medium

    CVE-2002-1609

    Last Modified: 16 Apr 2026

    Buffer overflow in binmail in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.

    Published: 30 Aug 2002
    5
    Medium

    CVE-2002-0835

    Last Modified: 16 Apr 2026

    Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (VOIP) phones.

    Published: 30 Aug 2002
    5
    Medium

    CVE-2002-1353

    Last Modified: 16 Apr 2026

    LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.

    Published: 29 Aug 2002
    4.6
    Medium

    CVE-2002-1402

    Last Modified: 16 Apr 2026

    Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.

    Published: 28 Aug 2002
    6.5
    Medium

    CVE-2002-1401

    Last Modified: 16 Apr 2026

    Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.

    Published: 28 Aug 2002
    10
    Critical

    CVE-2002-1572

    Last Modified: 16 Apr 2026

    Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.

    Published: 27 Aug 2002
    4.6
    Medium

    CVE-2002-1574

    Last Modified: 16 Apr 2026

    Buffer overflow in the ixj telephony card driver in Linux before 2.4.20 has unknown impact and attack vectors.

    Published: 26 Aug 2002
    10
    Critical

    CVE-2002-1573

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling."

    Published: 26 Aug 2002
    7.5
    High

    CVE-2002-0989

    Last Modified: 16 Apr 2026

    The URL handler in the manual browser option for Gaim before 0.59.1 allows remote attackers to execute arbitrary script via shell metacharacters in a link.

    Published: 25 Aug 2002
    5
    Medium

    CVE-2002-1451

    Last Modified: 16 Apr 2026

    Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character.

    Published: 24 Aug 2002
    7.5
    High

    CVE-2002-0724

    Last Modified: 16 Apr 2026

    Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".

    Published: 24 Aug 2002
    7.5
    High

    CVE-2002-0723

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

    Published: 24 Aug 2002
    5
    Medium

    CVE-2002-0983

    Last Modified: 16 Apr 2026

    IRC client irssi in irssi-text before 0.8.4 allows remote attackers to cause a denial of service (crash) via an IRC channel that has a long topic followed by a certain string, possibly triggering a buffer overflow.

    Published: 24 Aug 2002
    4.6
    Medium

    CVE-2002-0971

    Last Modified: 16 Apr 2026

    Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging System to bypass the VNC GUI and access the "Add new clients" dialogue box.

    Published: 23 Aug 2002
    5
    Medium

    CVE-2002-0978

    Last Modified: 16 Apr 2026

    Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.

    Published: 23 Aug 2002
    7.5
    High

    CVE-2002-0979

    Last Modified: 16 Apr 2026

    The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code.

    Published: 23 Aug 2002
    7.5
    High

    CVE-2002-0980

    Last Modified: 16 Apr 2026

    The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.

    Published: 23 Aug 2002
    7.5
    High

    CVE-2002-0861

    Last Modified: 16 Apr 2026

    Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.

    Published: 23 Aug 2002
    7.5
    High

    CVE-2002-0977

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to execute arbitrary code via a long TS value.

    Published: 23 Aug 2002
    4.6
    Medium

    CVE-2002-0973

    Last Modified: 16 Apr 2026

    Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl.

    Published: 23 Aug 2002
    7.5
    High

    CVE-2002-0975

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.

    Published: 23 Aug 2002
    6.4
    Medium

    CVE-2002-0976

    Last Modified: 16 Apr 2026

    Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.

    Published: 23 Aug 2002
    7.5
    High

    CVE-2002-0982

    Last Modified: 16 Apr 2026

    Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.

    Published: 23 Aug 2002
    5
    Medium

    CVE-2002-0986

    Last Modified: 16 Apr 2026

    The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."

    Published: 23 Aug 2002
    7.5
    High

    CVE-2002-0985

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands.

    Published: 23 Aug 2002
    7.2
    High

    CVE-2002-0093

    Last Modified: 16 Apr 2026

    Buffer overflow in ipcs for HP Tru64 UNIX 4.0f through 5.1a may allow attackers to execute arbitrary code, a different vulnerability than CVE-2001-0423.

    Published: 20 Aug 2002
    7.5
    High

    CVE-2002-0857

    Last Modified: 16 Apr 2026

    Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.

    Published: 20 Aug 2002
    10
    Critical

    CVE-2002-0721

    Last Modified: 16 Apr 2026

    Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

    Published: 20 Aug 2002
    7.5
    High

    CVE-2002-0858

    Last Modified: 16 Apr 2026

    catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges.

    Published: 20 Aug 2002
    7.5
    High

    CVE-2002-0870

    Last Modified: 16 Apr 2026

    The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.

    Published: 20 Aug 2002
    5
    Medium

    CVE-2002-0654

    Last Modified: 16 Apr 2026

    Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.

    Published: 20 Aug 2002
    5.5
    Medium

    CVE-2002-0725

    Last Modified: 16 Apr 2026

    NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file.

    Published: 20 Aug 2002
    5
    Medium

    CVE-2002-0874

    Last Modified: 16 Apr 2026

    Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.

    Published: 20 Aug 2002
    7.5
    High

    CVE-2002-0834

    Last Modified: 16 Apr 2026

    Buffer overflow in the ISIS dissector for Ethereal 0.9.5 and earlier allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.

    Published: 20 Aug 2002
    4.6
    Medium

    CVE-2002-0972

    Last Modified: 16 Apr 2026

    Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.

    Published: 20 Aug 2002
    7.5
    High

    CVE-2002-1400

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string.

    Published: 20 Aug 2002
    5
    Medium

    CVE-2002-1405

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

    Published: 19 Aug 2002
    7.5
    High

    CVE-2002-1397

    Last Modified: 16 Apr 2026

    Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.

    Published: 19 Aug 2002
    4.6
    Medium

    CVE-2002-1398

    Last Modified: 16 Apr 2026

    Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input."

    Published: 19 Aug 2002
    2.6
    Low

    CVE-2002-1444

    Last Modified: 16 Apr 2026

    The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function.

    Published: 15 Aug 2002
    4.3
    Medium

    CVE-2002-1453

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.

    Published: 14 Aug 2002
    7.5
    High

    CVE-2002-1452

    Last Modified: 16 Apr 2026

    Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.

    Published: 14 Aug 2002
    5
    Medium

    CVE-2002-0632

    Last Modified: 16 Apr 2026

    Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server.

    Published: 14 Aug 2002
    5
    Medium

    CVE-2002-0852

    Last Modified: 16 Apr 2026

    Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.

    Published: 14 Aug 2002
    7.2
    High

    CVE-2002-0854

    Last Modified: 16 Apr 2026

    Buffer overflows in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the i4l package on SuSE 7.3, 8.0, and possibly other operating systems, may allow local users to gain privileges.

    Published: 14 Aug 2002
    2.1
    Low

    CVE-2002-0871

    Last Modified: 16 Apr 2026

    xinetd 2.3.4 leaks file descriptors for the signal pipe to services that are launched by xinetd, which could allow those services to cause a denial of service via the pipe.

    Published: 13 Aug 2002