Latest CVE Feed
-
7.5
HIGHCVE-2002-1308
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1283
Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.... Read more
Affected Products : emframe- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1279
Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option).... Read more
Affected Products : masqmail- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1588
Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2 allows remote attackers to cause a denial of service (mailtool segmentation violation and crash) via a malformed mail attachment.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1290
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1293
The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1316
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separa... Read more
Affected Products : iplanet_web_server- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1276
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1219
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1307
Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.... Read more
Affected Products : mhonarc- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1142
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stu... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1204
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing... Read more
Affected Products : communicator- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1247
Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1311
Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files.... Read more
Affected Products : courier_mta- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1221
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1220
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1291
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0029
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) ... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1285
runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.... Read more
Affected Products : suse_linux- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1287
Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025