7.5
    High

    CVE-2002-0379

    Last Modified: 27 Oct 2016

    Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a long BODY request.

    Source:korty
    Published:10 May 2002
    5
    Medium

    CVE-2002-0375

    Last Modified: 22 Sept 2012

    Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter.

    Source:frog
    Published:9 May 2002
    7.5
    High

    CVE-2002-0371

    Last Modified: 24 Sept 2012

    Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.

    Published:15 Jun 2002
    7.8
    High

    CVE-2002-0367

    Last Modified: 23 Sept 2012

    smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

    Source:EliCZ
    Published:25 Jun 2002
    7.5
    High

    CVE-2002-0348

    Last Modified: 16 Apr 2026

    service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.

    Published:3 May 2002
    5
    Medium

    CVE-2002-0347

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.

    Published:3 May 2002
    7.5
    High

    CVE-2002-0346

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.

    Published:3 May 2002
    5
    Medium

    CVE-2002-0338

    Last Modified: 12 Sept 2012

    The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.

    Source:3APA3A
    Published:3 May 2002
    7.5
    High

    CVE-2002-0336

    Last Modified: 12 Sept 2012

    Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.

    Source:Limpid Byte
    Published:3 May 2002
    10
    Critical

    CVE-2002-0335

    Last Modified: 12 Sept 2012

    Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request.

    Source:Limpid Byte
    Published:3 May 2002
    5
    Medium

    CVE-2002-0333

    Last Modified: 12 Sept 2012

    Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument.

    Source:spybreak
    Published:3 May 2002
    7.5
    High

    CVE-2002-0332

    Last Modified: 12 Sept 2012

    Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostname that is determined using reverse DNS lookups, (2) a long AUTH string, or (3) certain data in the xtell request.

    Source:spybreak
    Published:3 May 2002
    5
    Medium

    CVE-2002-0331

    Last Modified: 12 Sept 2012

    Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request.

    Source:UNTER
    Published:3 May 2002
    7.5
    High

    CVE-2002-0330

    Last Modified: 23 Sept 2012

    Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag.

    Source:frog
    Published:25 Jun 2002
    7.5
    High

    CVE-2002-0329

    Last Modified: 12 Sept 2012

    Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag.

    Source:Justin
    Published:25 Jun 2002
    7.5
    High

    CVE-2002-0328

    Last Modified: 12 Sept 2012

    Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.

    Source:godminus
    Published:3 May 2002
    7.2
    High

    CVE-2002-0327

    Last Modified: 12 Sept 2012

    Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.

    Source:Haiku Hacker
    Published:3 May 2002
    5
    Medium

    CVE-2002-0325

    Last Modified: 12 Sept 2012

    Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.

    Source:Strumpf Noir Society
    Published:3 May 2002
    7.5
    High

    CVE-2002-0319

    Last Modified: 12 Sept 2012

    Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.

    Source:Jens Liebchen
    Published:3 May 2002
    7.5
    High

    CVE-2002-0316

    Last Modified: 12 Sept 2012

    Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag.

    Source:skizzik
    Published:3 May 2002
    7.5
    High

    CVE-2002-0313

    Last Modified: 12 Sept 2012

    Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.

    Source:B-r00t
    Published:25 Jun 2002
    10
    Critical

    CVE-2002-0311

    Last Modified: 10 Sept 2012

    Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.

    Source:jGgM
    Published:3 May 2002
    5
    Medium

    CVE-2002-0300

    Last Modified: 12 Sept 2012

    gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.

    Source:Thomas Springer
    Published:31 May 2002
    1.2
    Low

    CVE-2002-0296

    Last Modified: 12 Sept 2012

    The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.

    Source:Larry W. Cashdollar
    Published:3 May 2002
    5
    Medium

    CVE-2002-0289

    Last Modified: 12 Sept 2012

    Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.

    Source:Alex Hernandez
    Published:3 May 2002
    5
    Medium

    CVE-2002-0288

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.

    Source:Alex Hernandez
    Published:3 May 2002
    7.5
    High

    CVE-2002-0280

    Last Modified: 1 Oct 2012

    Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply.

    Source:doe
    Published:3 May 2002
    7.5
    High

    CVE-2002-0276

    Last Modified: 12 Sept 2012

    Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2000, allows remote attackers to execute arbitrary code via large packets.

    Source:Fermín J. Serna
    Published:31 May 2002
    5
    Medium

    CVE-2002-0266

    Last Modified: 12 Sept 2012

    Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.

    Source:phinegeek
    Published:3 May 2002
    4.6
    Medium

    CVE-2002-0265

    Last Modified: 12 Sept 2012

    Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file.

    Source:darky0da
    Published:29 May 2002
    7.5
    High

    CVE-2002-0263

    Last Modified: 12 Sept 2012

    Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, or (3) ezadmin.cgi.

    Source:Jin Ho You
    Published:3 May 2002
    5
    Medium

    CVE-2002-0256

    Last Modified: 16 Apr 2026

    The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, which causes a large number of login failures and causes the telnet service to stop.

    Source:Fabian Ramirez
    Published:3 May 2002
    7.5
    High

    CVE-2002-0252

    Last Modified: 25 Oct 2016

    Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header.

    Source:Subreption LLC.
    Published:3 May 2002
    7.5
    High

    CVE-2002-0250

    Last Modified: 12 Sept 2012

    Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch's configuration and modify the administrator password.

    Source:Tamer Sahin
    Published:29 May 2002
    7.2
    High

    CVE-2002-0246

    Last Modified: 12 Sept 2012

    Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.

    Source:jGgM
    Published:29 May 2002
    7.5
    High

    CVE-2002-0244

    Last Modified: 6 Sept 2016

    Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.

    Source:Jedi/Sector
    Published:3 May 2002
    7.2
    High

    CVE-2002-0239

    Last Modified: 12 Sept 2012

    Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.

    Source:Xpl017Elz
    Published:3 May 2002
    7.5
    High

    CVE-2002-0236

    Last Modified: 9 Sept 2012

    Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.

    Source:Mark Cooper
    Published:3 May 2002
    7.5
    High

    CVE-2002-0231

    Last Modified: 12 Sept 2012

    Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.

    Source:James Martin
    Published:3 May 2002
    5
    Medium

    CVE-2002-0230

    Last Modified: 11 Sept 2012

    Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.

    Source:superpetz
    Published:3 May 2002
    7.5
    High

    CVE-2002-0229

    Last Modified: 11 Sept 2012

    Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

    Source:Dave Wilson
    Published:3 May 2002
    5
    Medium

    CVE-2002-0227

    Last Modified: 11 Sept 2012

    KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.

    Source:Rafael San Miguel Carrasco
    Published:3 May 2002
    5
    Medium

    CVE-2002-0215

    Last Modified: 11 Sept 2012

    Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.

    Source:superpetz
    Published:3 May 2002
    6.2
    Medium

    CVE-2002-0211

    Last Modified: 11 Sept 2012

    Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.

    Source:Larry Cashdollar
    Published:16 May 2002
    7.2
    High

    CVE-2002-0210

    Last Modified: 11 Sept 2012

    setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.

    Source:Andrew Griffiths
    Published:3 May 2002
    5
    Medium

    CVE-2002-0209

    Last Modified: 11 Sept 2012

    Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with a half-closed session, which causes ACEdirector to send packets from the server without changing the address to the virtual IP address.

    Source:Dave Plonka
    Published:16 May 2002
    7.5
    High

    CVE-2002-0207

    Last Modified: 9 Sept 2012

    Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds the actual length of the header.

    Source:UNYUN
    Published:16 May 2002
    7.5
    High

    CVE-2002-0206

    Last Modified: 10 Sept 2012

    index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.

    Source:Handle Nopman
    Published:3 May 2002
    5
    Medium

    CVE-2002-0201

    Last Modified: 10 Sept 2012

    Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.

    Source:Alex Hernandez
    Published:3 May 2002
    5
    Medium

    CVE-2002-0200

    Last Modified: 16 Apr 2026

    Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.

    Published:3 May 2002