7.2
    High

    CVE-2003-0004

    Last Modified: 24 Oct 2012

    Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter.

    Source:Nsfocus
    Published:19 Feb 2003
    7.5
    High

    CVE-2003-0003

    Last Modified: 22 Nov 2017

    Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.

    Source:Marcin Wolak
    Published:7 Feb 2003
    6.8
    Medium

    CVE-2003-0002

    Last Modified: 12 Oct 2012

    Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.

    Source:overclocking_a_la_abuela
    Published:7 Feb 2003
    5.3
    Medium

    CVE-2003-0001

    Last Modified: 21 Sept 2016

    Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

    Source:Jon Hart
    Published:6 Jan 2003
    7.5
    High

    CVE-2002-20001

    Last Modified: 22 Aug 2025

    The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

    Published:11 Nov 2021
    10
    Critical

    CVE-2002-2425

    Last Modified: 2 Oct 2012

    Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.

    Source:ghandi
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2424

    Last Modified: 6 Oct 2012

    Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag.

    Source:Matthew Murphy
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2422

    Last Modified: 9 Oct 2012

    Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message.

    Source:Taylor Huff
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2420

    Last Modified: 7 Oct 2012

    site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.

    Source:luca.ercoli
    Published:31 Dec 2002
    10
    Critical

    CVE-2002-2417

    Last Modified: 17 Oct 2012

    acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.

    Source:Matthew Murphy
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2416

    Last Modified: 18 Oct 2012

    Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.

    Source:mikecc
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2404

    Last Modified: 16 Oct 2012

    Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110).

    Source:securma massine
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2403

    Last Modified: 16 Oct 2012

    Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.

    Source:mattmurphy
    Published:31 Dec 2002
    10
    Critical

    CVE-2002-2400

    Last Modified: 16 Oct 2012

    Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP POST request.

    Source:Xpl017Elz
    Published:31 Dec 2002
    6.4
    Medium

    CVE-2002-2399

    Last Modified: 16 Oct 2012

    Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Tim Brown
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2385

    Last Modified: 16 Oct 2012

    Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL containing a long voice phone number.

    Source:S G Masood
    Published:31 Dec 2002
    7.8
    High

    CVE-2002-2379

    Last Modified: 14 Oct 2012

    Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service (crash) via a port scan, possibly due to an ssh bug. NOTE: this issue could not be reproduced by the vendor

    Source:Thomas Munn
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2376

    Last Modified: 28 Sept 2012

    Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue might overlap CVE-2005-1605.

    Source:DownBload
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2370

    Last Modified: 7 Oct 2012

    SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.

    Source:saman
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2362

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.

    Source:qber66
    Published:31 Dec 2002
    9.3
    Critical

    CVE-2002-2360

    Last Modified: 7 Oct 2012

    The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.

    Source:Noam Rathaus
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2359

    Last Modified: 3 Oct 2012

    Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.

    Source:Eiji James Yoshida
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2358

    Last Modified: 3 Oct 2012

    Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL.

    Source:Eiji James Yoshida
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2357

    Last Modified: 16 Oct 2012

    MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string, possibly due to a buffer overflow.

    Source:redsand
    Published:31 Dec 2002
    6.4
    Medium

    CVE-2002-2353

    Last Modified: 16 Oct 2012

    tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.

    Source:Aviram Jenik
    Published:31 Dec 2002
    6.4
    Medium

    CVE-2002-2351

    Last Modified: 3 Oct 2012

    Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).

    Source:Paul Szabo
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2349

    Last Modified: 13 Oct 2012

    phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.

    Source:Roland Verlander
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2348

    Last Modified: 12 Oct 2012

    Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter.

    Source:Max
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2343

    Last Modified: 22 Sept 2012

    Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email messages.

    Source:ppp-design
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2341

    Last Modified: 22 Sept 2012

    Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to inject arbitrary web script or HTML via a blocked URL.

    Source:E M
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2339

    Last Modified: 11 Oct 2012

    Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in (1) image, (2) img, (3) image=right, (4) img=right, (5) image=left, and (6) img=left tags.

    Source:frog
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2338

    Last Modified: 26 Sept 2012

    The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.

    Source:eldre8
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2336

    Last Modified: 11 Oct 2012

    Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.

    Source:Yiming Gong
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2335

    Last Modified: 11 Oct 2012

    Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.

    Source:frog
    Published:31 Dec 2002
    7.8
    High

    CVE-2002-2325

    Last Modified: 1 Oct 2012

    The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.

    Source:Martin J. Muench
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2321

    Last Modified: 11 Oct 2012

    Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

    Source:Sp.IC
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2319

    Last Modified: 11 Oct 2012

    Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.

    Source:frog
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2318

    Last Modified: 3 Oct 2012

    Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.

    Source:Matt Murphy
    Published:31 Dec 2002
    7.8
    High

    CVE-2002-2315

    Last Modified: 22 Sept 2012

    Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router.

    Source:FX
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2314

    Last Modified: 1 Oct 2012

    Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.

    Source:Andreas Sandblad
    Published:31 Dec 2002
    5.8
    Medium

    CVE-2002-2312

    Last Modified: 1 Oct 2012

    Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.

    Source:Andreas Sandblad
    Published:31 Dec 2002
    7.8
    High

    CVE-2002-2309

    Last Modified: 1 Oct 2012

    php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.

    Source:Matthew Murphy
    Published:31 Dec 2002
    7.8
    High

    CVE-2002-2306

    Last Modified: 1 Oct 2012

    Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages.

    Source:Josh & omega
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2304

    Last Modified: 19 Oct 2012

    SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.

    Source:frog
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2300

    Last Modified: 18 Oct 2012

    Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command.

    Source:Michael S. Scheidell
    Published:31 Dec 2002
    6.8
    Medium

    CVE-2002-2298

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

    Source:Drago84
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2296

    Last Modified: 28 Nov 2017

    Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.

    Source:Fabricio Angeletti
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2295

    Last Modified: 18 Oct 2012

    Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an off-by-one buffer overflow, or (2) a long method name in an HTTP request, (3) a long version number in an HTTP request, (4) a long User-Agent header, or (5) a long file path.

    Source:Matthew Murphy
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2288

    Last Modified: 19 Oct 2012

    Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.

    Source:euronymous
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2287

    Last Modified: 16 Oct 2012

    PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

    Source:Hai Nam Luke
    Published:31 Dec 2002