7.5
    High

    CVE-2002-1643

    Last Modified: 7 Mar 2011

    Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.

    Source:Metasploit
    Published:19 Dec 2002
    5
    Medium

    CVE-2002-1634

    Last Modified: 23 Sept 2012

    Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl, (5) volscgi.pl, (6) lancgi.pl, (7) test.jse, or (8) env.pl.

    Source:Procheckup
    Published:31 Dec 2002
    7.2
    High

    CVE-2002-1616

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc.

    Source:K2
    Published:1 Aug 2002
    7.2
    High

    CVE-2002-1614

    Last Modified: 16 Apr 2026

    Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.

    Source:Cody Tubbs
    Published:9 Sept 2002
    7.5
    High

    CVE-2002-1605

    Last Modified: 7 Oct 2012

    Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET environment variable to (1) dxpause, (2) dxconsole, or (3) dtsession.

    Source:stripey
    Published:2 Sept 2002
    5
    Medium

    CVE-2002-1603

    Last Modified: 16 Dec 2012

    GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.

    Source:Luigi Auriemma
    Published:13 Feb 2002
    4.6
    Medium

    CVE-2002-1602

    Last Modified: 20 Sept 2012

    Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.

    Source:Gobbles Security
    Published:23 Apr 2002
    5
    Medium

    CVE-2002-1581

    Last Modified: 14 Oct 2012

    Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter.

    Source:pokleyzz
    Published:6 Jul 2004
    7.5
    High

    CVE-2002-1580

    Last Modified: 18 Oct 2012

    Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.

    Source:Timo Sirainen
    Published:20 May 2004
    7.2
    High

    CVE-2002-1576

    Last Modified: 18 Oct 2012

    lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called from a directory that has a symlink to the lserver program.

    Source:SAP Security
    Published:16 Mar 2004
    7.5
    High

    CVE-2002-1570

    Last Modified: 9 Sept 2012

    Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variable data past the end of an array.

    Source:Juan M. de la Torre
    Published:30 Oct 2003
    6.8
    Medium

    CVE-2002-1567

    Last Modified: 4 Oct 2012

    Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

    Source:Skinnay
    Published:19 Sept 2003
    5
    Medium

    CVE-2002-1566

    Last Modified: 7 Oct 2012

    netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to cause a denial of service (crash) via a long string to port 9284.

    Source:V9
    Published:15 Aug 2003
    5
    Medium

    CVE-2002-1561

    Last Modified: 2 Jan 2014

    The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.

    Source:lion
    Published:26 Mar 2003
    10
    Critical

    CVE-2002-1560

    Last Modified: 2 Jan 2014

    index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.

    Source:frog
    Published:31 Mar 2003
    5
    Medium

    CVE-2002-1559

    Last Modified: 14 Oct 2012

    Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.

    Source:Zero X
    Published:18 Mar 2003
    7.5
    High

    CVE-2002-1549

    Last Modified: 16 Oct 2012

    Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:Xpl017Elz
    Published:31 Mar 2003
    5
    Medium

    CVE-2002-1542

    Last Modified: 25 Oct 2017

    SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.

    Source:D4rkGr3y
    Published:18 Mar 2003
    5
    Medium

    CVE-2002-1539

    Last Modified: 14 Oct 2012

    Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.

    Source:D4rkGr3y
    Published:18 Mar 2003
    5.8
    Medium

    CVE-2002-1533

    Last Modified: 10 Oct 2012

    Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).

    Source:Skinnay
    Published:18 Mar 2003
    5
    Medium

    CVE-2002-1530

    Last Modified: 12 Oct 2012

    The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.

    Source:ken@FTU
    Published:31 Mar 2003
    4.3
    Medium

    CVE-2002-1529

    Last Modified: 12 Oct 2012

    Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter.

    Source:ken@FTU
    Published:31 Mar 2003
    5
    Medium

    CVE-2002-1527

    Last Modified: 10 Oct 2012

    emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message.

    Source:FVS
    Published:18 Mar 2003
    4.3
    Medium

    CVE-2002-1526

    Last Modified: 10 Oct 2012

    Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field.

    Source:FVS
    Published:18 Mar 2003
    5
    Medium

    CVE-2002-1525

    Last Modified: 10 Oct 2012

    Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.

    Source:ET LoWNOISE
    Published:18 Mar 2003
    5
    Medium

    CVE-2002-1522

    Last Modified: 11 Oct 2012

    Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.

    Source:Morgan
    Published:18 Mar 2003
    7.2
    High

    CVE-2002-1514

    Last Modified: 10 Oct 2012

    gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.

    Source:grazer
    Published:2 Apr 2003
    4.6
    Medium

    CVE-2002-1513

    Last Modified: 9 Oct 2012

    The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges.

    Source:Mike Riley
    Published:2 Apr 2003
    6.2
    Medium

    CVE-2002-1512

    Last Modified: 7 Oct 2012

    xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file.

    Source:prophecy
    Published:18 Mar 2003
    7.2
    High

    CVE-2002-1506

    Last Modified: 6 Oct 2012

    Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated.

    Source:RaiSe
    Published:18 Mar 2003
    7.5
    High

    CVE-2002-1505

    Last Modified: 7 Oct 2012

    SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.

    Source:Cano2
    Published:2 Apr 2003
    7.2
    High

    CVE-2002-1503

    Last Modified: 15 Nov 2017

    Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdcmd, (3) afd_ctrl, (4) init_afd, (5) mafd, (6) mon_ctrl, (7) show_olog, or (8) udc.

    Source:eSDee
    Published:18 Mar 2003
    5
    Medium

    CVE-2002-1501

    Last Modified: 7 Oct 2012

    The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078.

    Source:Mella Marco
    Published:2 Apr 2003
    7.5
    High

    CVE-2002-1499

    Last Modified: 7 Oct 2012

    Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp.

    Source:Matthew Murphy
    Published:18 Mar 2003
    4.3
    Medium

    CVE-2002-1497

    Last Modified: 7 Oct 2012

    Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response.

    Source:Matthew Murphy
    Published:2 Apr 2003
    7.5
    High

    CVE-2002-1496

    Last Modified: 9 Oct 2012

    Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header.

    Source:eSDee
    Published:2 Apr 2003
    4.3
    Medium

    CVE-2002-1495

    Last Modified: 9 Oct 2012

    Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that are displayed in a pop-up window, and (3) certain malicious attributes within otherwise safe tags, such as onMouseOver.

    Source:Ulf Harnhammar
    Published:18 Mar 2003
    4.3
    Medium

    CVE-2002-1494

    Last Modified: 7 Oct 2012

    Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.

    Published:2 Apr 2003
    4.3
    Medium

    CVE-2002-1493

    Last Modified: 8 Oct 2012

    Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag.

    Source:Matthew Murphy
    Published:2 Apr 2003
    7.2
    High

    CVE-2002-1492

    Last Modified: 8 Oct 2012

    Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.

    Source:BrainStorm
    Published:18 Mar 2003
    7.5
    High

    CVE-2002-1489

    Last Modified: 8 Oct 2012

    Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.

    Source:UkR-XblP
    Published:18 Mar 2003
    5
    Medium

    CVE-2002-1488

    Last Modified: 9 Oct 2012

    The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian user is not in.

    Source:Lance Fitz-Herbert
    Published:18 Mar 2003
    5
    Medium

    CVE-2002-1487

    Last Modified: 9 Oct 2012

    The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, (7) 218, (8) 243, (9) 302, (10) 317, (11) 324, (12) 332, (13) 333, (14) 352, and (15) 367.

    Source:Lance Fitz-Herbert
    Published:18 Mar 2003
    7.5
    High

    CVE-2002-1486

    Last Modified: 9 Oct 2012

    Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.

    Source:Lance Fitz-Herbert
    Published:18 Mar 2003
    9.8
    Critical

    CVE-2002-1484

    Last Modified: 8 Oct 2012

    DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.

    Source:Stefan Bagdohn
    Published:18 Mar 2003
    5
    Medium

    CVE-2002-1483

    Last Modified: 8 Oct 2012

    db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).

    Source:Stefan Bagdohn
    Published:18 Mar 2003
    10
    Critical

    CVE-2002-1482

    Last Modified: 7 Oct 2012

    SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.

    Source:ppp-design
    Published:18 Mar 2003
    7.5
    High

    CVE-2002-1481

    Last Modified: 7 Oct 2012

    savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.

    Source:ppp-design
    Published:18 Mar 2003
    6.8
    Medium

    CVE-2002-1480

    Last Modified: 7 Oct 2012

    Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.

    Source:ppp-design
    Published:18 Mar 2003
    4.6
    Medium

    CVE-2002-1473

    Last Modified: 6 Mar 2011

    Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

    Source:Metasploit
    Published:18 Mar 2003