Latest CVE Feed
-
5.0
MEDIUMCVE-2002-1362
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1365
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local address... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1361
overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.... Read more
Affected Products : cobalt_raq_4- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1373
Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.... Read more
Affected Products : mysql- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1296
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1382
Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846.... Read more
Affected Products : flash_player- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1257
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.... Read more
Affected Products : windows_2000 windows_xp windows_95 windows_98 windows_nt windows_98se windows_me windows_2000_terminal_services- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1380
Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1377
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.... Read more
Affected Products : vim- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1375
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1643
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simu... Read more
Affected Products : helix_universal_server- Published: Dec. 19, 2002
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2002-1347
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during ... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1340
The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception.... Read more
Affected Products : office_web_components- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1354
Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.... Read more
Affected Products : typsoft_ftp_server- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1344
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1158
Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.... Read more
Affected Products : canna- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1341
Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1339
The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.... Read more
Affected Products : office_web_components- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1338
The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.... Read more
Affected Products : office_web_components- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1159
Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025