Latest CVE Feed
-
5.0
MEDIUMCVE-2002-1320
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").... Read more
Affected Products : pine- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1336
TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1323
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.... Read more
Affected Products : enterprise_linux solaris sunos unixware linux_advanced_workstation irix open_unix safe.pm linux- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1335
Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.... Read more
Affected Products : w3m- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1587
The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.... Read more
- Published: Dec. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1586
Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.... Read more
- Published: Dec. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1588
Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2 allows remote attackers to cause a denial of service (mailtool segmentation violation and crash) via a malformed mail attachment.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0029
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) ... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1307
Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.... Read more
Affected Products : mhonarc- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1221
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1220
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1291
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1204
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing... Read more
Affected Products : communicator- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1284
The wizard in KGPG 0.6 through 0.8.2 does not properly provide the passphrase to gpg when creating new keys, which causes secret keys to be created with an empty passphrase and allows local attackers to steal the keys if they can be read.... Read more
Affected Products : kgpg- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1289
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instanc... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1294
The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other una... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1309
Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary via an HTTP GET request with a long .cfm file name.... Read more
Affected Products : coldfusion- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1247
Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1283
Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.... Read more
Affected Products : emframe- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1295
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private c... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025