10
    Critical

    CVE-2002-2281

    Last Modified: 22 Oct 2012

    Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler.

    Source:Last Stage of Delirium
    Published:31 Dec 2002
    7.8
    High

    CVE-2002-2272

    Last Modified: 19 Dec 2016

    Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.

    Source:Sapient2003
    Published:31 Dec 2002
    9.4
    Critical

    CVE-2002-2268

    Last Modified: 27 Oct 2016

    Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.

    Source:Metasploit
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2258

    Last Modified: 18 Oct 2012

    Moby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large integer or (2) non-numeric value in the Content-Length header, which causes an access violation after a failed atoi function call.

    Source:Matthew Murphy
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2255

    Last Modified: 18 Oct 2012

    Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.

    Source:f_a_a
    Published:31 Dec 2002
    10
    Critical

    CVE-2002-2251

    Last Modified: 18 Oct 2012

    Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a long argument.

    Source:Xpl017Elz
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2249

    Last Modified: 17 Oct 2012

    PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.

    Source:frog
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2247

    Last Modified: 19 Oct 2012

    The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.

    Source:euronymous
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2246

    Last Modified: 19 Oct 2012

    Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.

    Source:Ory Segal
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2235

    Last Modified: 17 Oct 2012

    member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.

    Source:Sp.IC
    Published:31 Dec 2002
    8.5
    High

    CVE-2002-2232

    Last Modified: 19 Oct 2012

    Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.

    Source:Tamer Sahin
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2226

    Last Modified: 17 Oct 2012

    Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument.

    Source:Aviram Jenik
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2219

    Last Modified: 20 Oct 2012

    chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field.

    Source:Victor Pereira
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2200

    Last Modified: 14 Oct 2012

    Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) index.php, or (4) newtopic.php.

    Source:frog
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2195

    Last Modified: 29 Sept 2012

    Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.

    Source:anonymous
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2193

    Last Modified: 14 Oct 2012

    Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter.

    Source:Daniel Boland
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2192

    Last Modified: 15 Oct 2012

    Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders.

    Source:Matthew Murphy
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2191

    Last Modified: 15 Oct 2012

    Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non-existent .nsf database, which leaks the version in the HTTP banner.

    Source:Frank Perreault
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2190

    Last Modified: 15 Oct 2012

    ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.

    Source:Zero-X
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2178

    Last Modified: 11 Oct 2012

    Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag.

    Source:Sp.IC
    Published:31 Dec 2002
    10
    Critical

    CVE-2002-2176

    Last Modified: 1 Oct 2012

    SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.

    Source:langtuhaohoa caothuvolam
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2174

    Last Modified: 3 Oct 2012

    The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) via a large number of connections.

    Source:Stan Bubrouski
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2171

    Last Modified: 9 Oct 2012

    Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL.

    Source:DownBload
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2170

    Last Modified: 1 Oct 2012

    Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.

    Source:Matthew Murphy
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2169

    Last Modified: 30 Sept 2012

    Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.

    Source:orb
    Published:31 Dec 2002
    2.1
    Low

    CVE-2002-2165

    Last Modified: 30 Sept 2012

    The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.

    Source:Security Bugware
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2164

    Last Modified: 22 Oct 2012

    Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.

    Source:Stefano Zanero
    Published:31 Dec 2002
    4.6
    Medium

    CVE-2002-2162

    Last Modified: 7 Oct 2012

    Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts.

    Source:Coeus Group
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2154

    Last Modified: 9 Oct 2012

    Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.

    Source:DownBload
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2149

    Last Modified: 1 Oct 2012

    Buffer overflow in Lucent Access Point 300, 600, and 1500 Service Routers allows remote attackers to cause a denial of service (reboot) via a long HTTP request to the administrative interface.

    Source:FX
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2145

    Last Modified: 8 Oct 2012

    Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a '.' (%2e) at the end of the filename.

    Source:Auriemma Luigi
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2143

    Last Modified: 11 Oct 2012

    The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.

    Source:frog
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2134

    Last Modified: 20 Oct 2012

    haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to reference a URL on a remote web server that contains the code in a lang.php file.

    Source:frog
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2129

    Last Modified: 20 Oct 2012

    Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.

    Source:xatr0z
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2113

    Last Modified: 11 Sept 2012

    search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter.

    Source:Aleksey Sintsov
    Published:31 Dec 2002
    7.5
    High

    CVE-2002-2106

    Last Modified: 10 Sept 2012

    PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP code via the TemplateDir variable, as demonstrated using conflict.php.

    Source:Scott Moonen
    Published:31 Dec 2002
    2.1
    Low

    CVE-2002-2105

    Last Modified: 23 Sept 2012

    Microsoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file.

    Source:mosestycoon
    Published:31 Dec 2002
    4.6
    Medium

    CVE-2002-2087

    Last Modified: 10 Feb 2016

    Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_drop, (2) gds_lock_mgr, or (3) gds_inet_server.

    Source:bob
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2084

    Last Modified: 12 Sept 2012

    Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2) topic parameters.

    Source:frog
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2073

    Last Modified: 11 Sept 2012

    Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp.

    Source:rain forest puppy
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2072

    Last Modified: 11 Sept 2012

    java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause a denial of service (JVM crash) via a Java program that calls the doPrivileged method with a null argument.

    Source:Taeho Oh
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2071

    Last Modified: 11 Sept 2012

    Compaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lockd, (5) snmp, (6) ttdbserverd, and possibly other services via a TCP SYN scan, as demonstrated using nmap.

    Source:Luca Papotti
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2062

    Last Modified: 24 Sept 2012

    Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.

    Source:Eiji James Yoshida
    Published:31 Dec 2002
    4.3
    Medium

    CVE-2002-2055

    Last Modified: 24 Sept 2012

    Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:frog
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-2042

    Last Modified: 23 Sept 2012

    ptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, which could allow local users to execute arbitrary code by modifying running processes.

    Source:badc0ded
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-2041

    Last Modified: 15 Nov 2017

    Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.

    Source:badc0ded
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-2040

    Last Modified: 23 Sept 2012

    The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.

    Source:badc0ded
    Published:31 Dec 2002
    2.1
    Low

    CVE-2002-2039

    Last Modified: 23 Sept 2012

    /bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.

    Source:badc0ded
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2032

    Last Modified: 10 Sept 2012

    sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php.

    Source:zataz.com
    Published:31 Dec 2002
    5
    Medium

    CVE-2002-2031

    Last Modified: 9 Sept 2012

    Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event handler to monitor the results.

    Source:Tom Micklovitch
    Published:31 Dec 2002