Latest CVE Feed
-
2.1
LOWCVE-2002-1193
tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.... Read more
Affected Products : tkmail- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1118
TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1195
Cross-site scripting vulnerability (XSS) in the PHP interface for ht://Check 1.1 allows remote web servers to insert arbitrary HTML, including script, via a web page.... Read more
Affected Products : ht_check- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1198
Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.... Read more
Affected Products : bugzilla- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1212
Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.... Read more
Affected Products : webserver_4_all- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1217
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document ... Read more
Affected Products : internet_explorer- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1229
Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2002-1222
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.... Read more
Affected Products : catos- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1199
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1192
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1227
PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.... Read more
Affected Products : pam- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1214
Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1190
Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.... Read more
Affected Products : unity_server- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1215
Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 694 (incorrectly claimed as TCP in some sources).... Read more
Affected Products : heartbeat- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1226
Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).... Read more
Affected Products : heimdal- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1589
Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of service (system panic).... Read more
- Published: Oct. 24, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1451
Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT request... Read more
Affected Products : windows_2000- Published: Oct. 22, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1618
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.... Read more
- Published: Oct. 16, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1150
The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL... Read more
Affected Products : netmeeting- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0866
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc wi... Read more
Affected Products : virtual_machine- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025