Latest CVE Feed
-
5.0
MEDIUMCVE-2002-1033
Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot variant) in the argument.... Read more
Affected Products : i-runbook- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1020
The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook even when the maximum number of loans is exceeded by accessing the "Add to bookbag" feature when the server reports that no more copies are available.... Read more
Affected Products : adobe_content_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0922
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to d... Read more
Affected Products : csnews- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0929
Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests.... Read more
Affected Products : netware- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0913
Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response.... Read more
Affected Products : slurp- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0953
globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to execute arbitrary PHP code via a URL to the code in the LangCookie parameter.... Read more
Affected Products : php_address- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0938
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.... Read more
Affected Products : secure_access_control_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0878
SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0966
Buffer overflow in 4D web server 6.7.3 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request.... Read more
Affected Products : 4d_webserver- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-0934
Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _... Read more
Affected Products : alienform2- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0917
CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users.... Read more
Affected Products : cspassword- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0919
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page.... Read more
Affected Products : cspassword- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-0882
The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) t... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0910
Buffer overflows in netstd 3.07-17 package allows remote DNS servers to execute arbitrary code via a long FQDN reply, as observed in the utilities (1) linux-ftpd, (2) pcnfsd, (3) tftp, (4) traceroute, or (5) from/to.... Read more
Affected Products : netstd- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0944
Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program.... Read more
Affected Products : livestats- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0885
Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error.... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0891
The web interface (WebUI) of NetScreen ScreenOS before 2.6.1r8, and certain 2.8.x and 3.0.x versions before 3.0.3r1, allows remote attackers to cause a denial of service (crash) via a long user name.... Read more
Affected Products : netscreen_screenos- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0897
LocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that contains the "/./" directory.... Read more
Affected Products : localweb2000- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1094
Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1091
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025