7.5
    High

    CVE-2002-0953

    Last Modified: 27 Sept 2012

    globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to execute arbitrary PHP code via a URL to the code in the LangCookie parameter.

    Source:Tim Vandermeerch
    Published:4 Oct 2002
    10
    Critical

    CVE-2002-0951

    Last Modified: 26 Sept 2012

    SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password.

    Source:Alexander Korchagin
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0949

    Last Modified: 24 Sept 2012

    Telindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which generates a reply that includes the router's password and other sensitive information in cleartext.

    Source:rubik
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0948

    Last Modified: 26 Sept 2012

    Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.

    Source:b0iler
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0946

    Last Modified: 26 Sept 2012

    Directory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files via ..\ (dot dot) sequences in an HTTP request.

    Source:Kistler Ueli
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-0942

    Last Modified: 27 Sept 2012

    Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long arguments to the extended stored procedures (1) xp_logattach_StartProf, (2) xp_logattach_setport, or (3) xp_logattach.

    Source:Martin Rakhmanoff
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0938

    Last Modified: 27 Sept 2012

    Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.

    Source:Dave Palumbo
    Published:4 Oct 2002
    5
    Medium

    CVE-2002-0937

    Last Modified: 26 Sept 2012

    The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).

    Source:Marc Schoenefeld
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0936

    Last Modified: 26 Sept 2012

    The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).

    Source:Marc Schoenefeld
    Published:31 Aug 2002
    6.4
    Medium

    CVE-2002-0932

    Last Modified: 26 Sept 2012

    SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.

    Source:Ahmet Sabri ALPER
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0931

    Last Modified: 26 Sept 2012

    Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" parameter to the index.php script with the (3) tickettime, (4) ticketfiles, or (5) updateticketlog operations, or (6) via the update section when a ticket is edited.

    Source:Ahmet Sabri ALPER
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0928

    Last Modified: 1 Oct 2012

    Buffer overflow in the Pirch 98 IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hyperlink in a channel or private message.

    Source:David Rude II
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0926

    Last Modified: 27 Sept 2012

    Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the MSPStoreID parameter.

    Source:Andrew Badr
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0923

    Last Modified: 26 Sept 2012

    CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.

    Source:Steve Gustin
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0922

    Last Modified: 26 Sept 2012

    CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.

    Source:Steve Gustin
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0919

    Last Modified: 23 Sept 2012

    CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page.

    Source:Steve Gustin
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0918

    Last Modified: 23 Sept 2012

    CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter, which generates an error.

    Source:Steve Gustin
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0913

    Last Modified: 24 Sept 2012

    Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response.

    Source:zillion
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0908

    Last Modified: 22 Sept 2012

    Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTPS request.

    Source:Andrew Lopacki
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0907

    Last Modified: 24 Sept 2012

    Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-".

    Source:eSDee
    Published:31 Aug 2002
    7.2
    High

    CVE-2002-0905

    Last Modified: 23 Sept 2012

    Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.

    Source:smurf
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0902

    Last Modified: 23 Sept 2012

    Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.

    Source:Martijn Boerwinkel
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0900

    Last Modified: 23 Sept 2012

    Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long search argument to the lookup capability.

    Source:Max
    Published:4 Oct 2002
    5
    Medium

    CVE-2002-0898

    Last Modified: 23 Sept 2012

    Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input type=file tag whose value contains a newline.

    Source:GreyMagic Software
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-0897

    Last Modified: 23 Sept 2012

    LocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that contains the "/./" directory.

    Source:Tamer Sahin
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-0895

    Last Modified: 23 Sept 2012

    Buffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PASS (password) command.

    Source:Kanatoko
    Published:4 Oct 2002
    5
    Medium

    CVE-2002-0894

    Last Modified: 23 Sept 2012

    NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet.

    Source:Matt Moore
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0893

    Last Modified: 23 Sept 2012

    Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences.

    Source:Matt Moore
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0892

    Last Modified: 23 Sept 2012

    The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message.

    Source:Matt Moore
    Published:4 Oct 2002
    2.1
    Low

    CVE-2002-0887

    Last Modified: 23 Sept 2012

    scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.

    Source:Kevin Finisterre
    Published:4 Oct 2002
    5
    Medium

    CVE-2002-0886

    Last Modified: 23 Sept 2012

    Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, which causes the TCP/IP stack to consume large amounts of memory.

    Source:blackangels
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0879

    Last Modified: 23 Sept 2012

    showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.

    Source:Richard Brain
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-0876

    Last Modified: 23 Sept 2012

    Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.

    Source:Shambala
    Published:31 Aug 2002
    2.1
    Low

    CVE-2002-0875

    Last Modified: 4 Oct 2012

    Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.

    Source:Michael Wardle
    Published:3 Jan 2002
    5
    Medium

    CVE-2002-0874

    Last Modified: 3 Oct 2012

    Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.

    Source:anonymous
    Published:20 Aug 2002
    7.5
    High

    CVE-2002-0866

    Last Modified: 8 Oct 2012

    Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka "DLL Execution via JDBC Classes."

    Source:anonymous
    Published:11 Oct 2002
    6.8
    Medium

    CVE-2002-0862

    Last Modified: 8 Oct 2012

    The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

    Source:Mike Benham
    Published:10 Sept 2002
    7.5
    High

    CVE-2002-0859

    Last Modified: 28 Sept 2012

    Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code.

    Source:NGSSoftware
    Published:5 Sept 2002
    7.5
    High

    CVE-2002-0855

    Last Modified: 1 Oct 2012

    Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.

    Source:office
    Published:11 Jul 2002
    7.2
    High

    CVE-2002-0851

    Last Modified: 3 Oct 2012

    Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog.

    Source:Gobbles Security
    Published:5 Sept 2002
    6.8
    Medium

    CVE-2002-0840

    Last Modified: 10 Oct 2012

    Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

    Source:mattmurphy
    Published:2 Oct 2002
    4.6
    Medium

    CVE-2002-0838

    Last Modified: 10 Oct 2012

    Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf.

    Source:zen-parse
    Published:26 Sept 2002
    7.5
    High

    CVE-2002-0833

    Last Modified: 3 Oct 2012

    Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part message with a long boundary string.

    Source:Kanatoko
    Published:7 Aug 2002
    Low

    CVE-2002-0828

    Last Modified: 8 Oct 2012

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0862. Reason: This is a duplicate of CVE-2002-0862. Notes: All CVE users should reference CVE-2002-0862 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Mike Benham
    Published:7 Aug 2002
    6.9
    Medium

    CVE-2002-0824

    Last Modified: 2 Oct 2012

    BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.

    Source:Sebastian Krahmer
    Published:12 Aug 2002
    7.5
    High

    CVE-2002-0823

    Last Modified: 23 Sept 2012

    Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.

    Source:Next Generation Security
    Published:12 Aug 2002
    7.2
    High

    CVE-2002-0817

    Last Modified: 2 Oct 2012

    Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.

    Source:gobbles
    Published:12 Aug 2002
    7.5
    High

    CVE-2002-0814

    Last Modified: 1 Oct 2012

    Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument.

    Source:Zag & Glcs
    Published:12 Aug 2002
    7.1
    High

    CVE-2002-0813

    Last Modified: 1 Oct 2012

    Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.

    Source:FX
    Published:12 Aug 2002
    6.4
    Medium

    CVE-2002-0812

    Last Modified: 3 Oct 2012

    Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.

    Source:Foundstone Inc.
    Published:10 Aug 2002