CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2002-0337

    Last Modified: 16 Apr 2026

    RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0340

    Last Modified: 16 Apr 2026

    Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via Trojan horse files containing .wmf content.

    Published: 3 May 2002
    4.6
    Medium

    CVE-2002-0343

    Last Modified: 16 Apr 2026

    Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0344

    Last Modified: 16 Apr 2026

    Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0348

    Last Modified: 16 Apr 2026

    service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0217

    Last Modified: 16 Apr 2026

    Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.

    Published: 3 May 2002
    7.2
    High

    CVE-2002-0219

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.

    Published: 3 May 2002
    4.6
    Medium

    CVE-2002-0225

    Last Modified: 16 Apr 2026

    tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0232

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.

    Published: 3 May 2002
    2.1
    Low

    CVE-2002-0234

    Last Modified: 16 Apr 2026

    NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0245

    Last Modified: 16 Apr 2026

    Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server's version name in the HTTP error message.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0252

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header.

    Published: 3 May 2002
    4.6
    Medium

    CVE-2002-0259

    Last Modified: 16 Apr 2026

    InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.

    Published: 3 May 2002
    7.2
    High

    CVE-2002-0268

    Last Modified: 16 Apr 2026

    Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.

    Published: 3 May 2002
    10
    Critical

    CVE-2002-0311

    Last Modified: 16 Apr 2026

    Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0315

    Last Modified: 16 Apr 2026

    fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0317

    Last Modified: 16 Apr 2026

    Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0325

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0338

    Last Modified: 16 Apr 2026

    The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0347

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.

    Published: 3 May 2002
    5
    Medium

    CVE-2001-1300

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.

    Published: 3 May 2002
    5
    Medium

    CVE-2001-1340

    Last Modified: 16 Apr 2026

    Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0201

    Last Modified: 16 Apr 2026

    Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.

    Published: 3 May 2002
    3.6
    Low

    CVE-2002-0202

    Last Modified: 16 Apr 2026

    PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) modify the server configuration via the world-writeable /oekaki/ folder.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0203

    Last Modified: 16 Apr 2026

    ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0204

    Last Modified: 16 Apr 2026

    Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to execute arbitrary code via a long command.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0205

    Last Modified: 16 Apr 2026

    Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0206

    Last Modified: 16 Apr 2026

    index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0200

    Last Modified: 16 Apr 2026

    Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0212

    Last Modified: 16 Apr 2026

    The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernames and makes it easier to conduct a brute force attack.

    Published: 3 May 2002
    2.1
    Low

    CVE-2002-0214

    Last Modified: 16 Apr 2026

    Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the WEP key from the registry key.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0220

    Last Modified: 16 Apr 2026

    phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0221

    Last Modified: 16 Apr 2026

    Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0222

    Last Modified: 16 Apr 2026

    Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0223

    Last Modified: 16 Apr 2026

    Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.

    Published: 3 May 2002
    7.2
    High

    CVE-2002-0218

    Last Modified: 16 Apr 2026

    Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0229

    Last Modified: 16 Apr 2026

    Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0230

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0231

    Last Modified: 16 Apr 2026

    Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0238

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.

    Published: 3 May 2002
    7.2
    High

    CVE-2002-0239

    Last Modified: 16 Apr 2026

    Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0240

    Last Modified: 16 Apr 2026

    PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.

    Published: 3 May 2002
    7.2
    High

    CVE-2002-0247

    Last Modified: 16 Apr 2026

    Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges.

    Published: 3 May 2002
    7.2
    High

    CVE-2002-0248

    Last Modified: 16 Apr 2026

    wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0249

    Last Modified: 16 Apr 2026

    PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.

    Published: 3 May 2002
    10
    Critical

    CVE-2002-0255

    Last Modified: 16 Apr 2026

    The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0256

    Last Modified: 16 Apr 2026

    The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, which causes a large number of login failures and causes the telnet service to stop.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0261

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.

    Published: 3 May 2002
    5
    Medium

    CVE-2002-0262

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in netget for Sybex E-Trainer web server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 3 May 2002
    7.5
    High

    CVE-2002-0263

    Last Modified: 16 Apr 2026

    Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, or (3) ezadmin.cgi.

    Published: 3 May 2002