7.5
    High

    CVE-2002-1375

    Last Modified: 22 Oct 2012

    The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.

    Source:Stefan Esser
    Published:12 Dec 2002
    7.5
    High

    CVE-2002-1374

    Last Modified: 2 Nov 2017

    The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.

    Source:Andi
    Published:12 Dec 2002
    7.5
    High

    CVE-2002-1368

    Last Modified: 20 Oct 2012

    Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.

    Source:iDefense
    Published:19 Dec 2002
    7.2
    High

    CVE-2002-1364

    Last Modified: 16 Oct 2012

    Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.

    Source:Carl Livitt
    Published:23 Dec 2002
    10
    Critical

    CVE-2002-1361

    Last Modified: 19 Oct 2012

    overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.

    Source:grazer
    Published:23 Dec 2002
    10
    Critical

    CVE-2002-1359

    Last Modified: 10 Mar 2011

    Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

    Source:Metasploit
    Published:17 Dec 2002
    5
    Medium

    CVE-2002-1351

    Last Modified: 16 Apr 2026

    Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request.

    Source:innerphobia
    Published:24 Dec 2002
    4.6
    Medium

    CVE-2002-1349

    Last Modified: 19 Oct 2012

    Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).

    Source:Joel Soderberg
    Published:18 Dec 2002
    10
    Critical

    CVE-2002-1337

    Last Modified: 15 Nov 2017

    Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

    Source:sd
    Published:3 Mar 2003
    6.8
    Medium

    CVE-2002-1334

    Last Modified: 18 Oct 2012

    Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

    Source:SecurityTracker.com
    Published:3 Dec 2002
    5
    Medium

    CVE-2002-1322

    Last Modified: 17 Oct 2012

    Rational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain packets to port 371, e.g. via nmap.

    Source:Stefan Bagdohn
    Published:27 Nov 2002
    5
    Medium

    CVE-2002-1320

    Last Modified: 7 Nov 2017

    Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").

    Source:lsjoberg
    Published:7 Nov 2002
    7.5
    High

    CVE-2002-1317

    Last Modified: 17 Oct 2012

    Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.

    Source:TESO Security
    Published:11 Dec 2002
    6.8
    Medium

    CVE-2002-1307

    Last Modified: 17 Oct 2012

    Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.

    Source:Steven Christey
    Published:29 Nov 2002
    7.5
    High

    CVE-2002-1275

    Last Modified: 14 Oct 2012

    Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."

    Source:Sebastian Krahmer
    Published:10 Nov 2002
    7.5
    High

    CVE-2002-1254

    Last Modified: 14 Oct 2012

    Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."

    Source:GreyMagic Software
    Published:27 Nov 2002
    7.2
    High

    CVE-2002-1250

    Last Modified: 27 Sept 2016

    Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument.

    Source:Girish
    Published:12 Nov 2002
    5
    Medium

    CVE-2002-1248

    Last Modified: 14 Oct 2012

    Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) via a GET request for a "%" URI.

    Source:Tamer Sahin
    Published:12 Nov 2002
    7.5
    High

    CVE-2002-1242

    Last Modified: 14 Oct 2012

    SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.

    Source:kill9
    Published:12 Nov 2002
    7.2
    High

    CVE-2002-1239

    Last Modified: 15 Oct 2012

    QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.

    Source:Texonet
    Published:12 Nov 2002
    7.5
    High

    CVE-2002-1238

    Last Modified: 15 Oct 2012

    Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.

    Source:Tamer Sahin
    Published:10 Nov 2002
    5
    Medium

    CVE-2002-1236

    Last Modified: 14 Oct 2012

    The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.

    Source:Jeep 94
    Published:12 Nov 2002
    4.6
    Medium

    CVE-2002-1230

    Last Modified: 12 Oct 2012

    NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation."

    Source:Serus
    Published:4 Nov 2002
    5
    Medium

    CVE-2002-1224

    Last Modified: 13 Oct 2012

    Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.

    Source:Ajay R Ramjatan
    Published:8 Oct 2002
    7.1
    High

    CVE-2002-1222

    Last Modified: 13 Oct 2012

    Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

    Source:blackangels
    Published:28 Oct 2002
    5
    Medium

    CVE-2002-1220

    Last Modified: 16 Oct 2012

    BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.

    Source:spybreak
    Published:29 Nov 2002
    7.5
    High

    CVE-2002-1217

    Last Modified: 13 Oct 2012

    Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.

    Source:GreyMagic Software
    Published:21 Oct 2002
    7.5
    High

    CVE-2002-1211

    Last Modified: 14 Oct 2012

    Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.

    Source:Karol Wiesek
    Published:12 Nov 2002
    5
    Medium

    CVE-2002-1209

    Last Modified: 14 Oct 2012

    Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.

    Source:Matthew Murphy
    Published:29 Oct 2002
    4.6
    Medium

    CVE-2002-1192

    Last Modified: 10 Oct 2012

    Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.

    Published:15 Oct 2002
    6.8
    Medium

    CVE-2002-1187

    Last Modified: 7 Oct 2012

    Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.

    Source:GreyMagic Software
    Published:11 Dec 2002
    7.5
    High

    CVE-2002-1183

    Last Modified: 8 Oct 2012

    Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).

    Source:Mike Benham
    Published:11 Dec 2002
    7.5
    High

    CVE-2002-1179

    Last Modified: 13 Oct 2012

    Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.

    Source:Noam Rathaus
    Published:28 Oct 2002
    5
    Medium

    CVE-2002-1178

    Last Modified: 11 Oct 2012

    Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.

    Source:Matt Moore
    Published:11 Oct 2002
    5
    Medium

    CVE-2002-1169

    Last Modified: 13 Oct 2012

    IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.

    Source:Rapid7
    Published:4 Nov 2002
    6.8
    Medium

    CVE-2002-1168

    Last Modified: 13 Oct 2012

    Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

    Source:Rapid7
    Published:25 Oct 2002
    6.8
    Medium

    CVE-2002-1167

    Last Modified: 13 Oct 2012

    Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

    Source:Rapid7
    Published:25 Oct 2002
    4.6
    Medium

    CVE-2002-1165

    Last Modified: 10 Oct 2012

    Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

    Source:zen-parse
    Published:1 Oct 2002
    7.2
    High

    CVE-2002-1155

    Last Modified: 15 Nov 2012

    Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.

    Source:wsxz
    Published:5 Jun 2003
    5
    Medium

    CVE-2002-1148

    Last Modified: 9 Oct 2012

    The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.

    Source:Rossen Raykov
    Published:24 Sept 2002
    7.1
    High

    CVE-2002-1147

    Last Modified: 9 Oct 2012

    The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program.

    Source:Brook Powers
    Published:11 Oct 2002
    5
    Medium

    CVE-2002-1143

    Last Modified: 8 Oct 2012

    Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."

    Source:Richard Edwards
    Published:3 Apr 2003
    7.5
    High

    CVE-2002-1142

    Last Modified: 8 Jun 2012

    Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.

    Source:Metasploit
    Published:29 Nov 2002
    7.5
    High

    CVE-2002-1135

    Last Modified: 9 Oct 2012

    modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code.

    Source:Tim Vandermeersch
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-1131

    Last Modified: 8 Oct 2012

    Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.

    Source:DarC KonQuest
    Published:16 Sept 2002
    7.2
    High

    CVE-2002-1129

    Last Modified: 8 Oct 2012

    Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.

    Source:stripey
    Published:24 Sept 2002
    2.1
    Low

    CVE-2002-1125

    Last Modified: 8 Oct 2012

    FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory.

    Source:badc0ded
    Published:17 Sept 2002
    7.5
    High

    CVE-2002-1123

    Last Modified: 10 Mar 2011

    Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.

    Source:Metasploit
    Published:24 Sept 2002
    7.5
    High

    CVE-2002-1120

    Last Modified: 27 Oct 2016

    Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:Jacopo Cervini
    Published:12 Sept 2002
    7.5
    High

    CVE-2002-1113

    Last Modified: 8 Jun 2018

    summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code.

    Source:Joao Gouveia
    Published:4 Oct 2002