Latest CVE Feed
-
5.0
MEDIUMCVE-2002-1093
HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request.... Read more
Affected Products : vpn_3000_concentrator_series_software- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0968
Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name.... Read more
Affected Products : simpleserver_www- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1060
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a n... Read more
Affected Products : cacheos- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1119
os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.... Read more
Affected Products : python- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0935
Apache Tomcat 4.0.3, and possibly other versions before 4.1.3 beta, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of requests to the server with null characters, which causes the working threads to hang.... Read more
Affected Products : tomcat- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1134
Unknown vulnerability in Compaq WEBES Service Tools 2.0 through WEBES 4.0 (Service Pack 5) allows local users to read privileged files.... Read more
Affected Products : webes_service_tools- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1104
Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).... Read more
Affected Products : vpn_client- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1098
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through t... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1110
Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php... Read more
Affected Products : mantis- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1112
Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.... Read more
Affected Products : mantis- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1102
The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1087
The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request.... Read more
Affected Products : ezcontents- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1078
Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters.... Read more
Affected Products : abyss_web_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1085
Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.... Read more
Affected Products : ezcontents- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1077
IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.... Read more
Affected Products : imail- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1043
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").... Read more
Affected Products : popcorn- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1099
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1008
Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered... Read more
Affected Products : lil_http_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1022
BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.... Read more
Affected Products : badblue- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1007
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.... Read more
Affected Products : blackboard- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025