Latest CVE Feed
-
7.2
HIGHCVE-2002-1871
pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark) in the (1) mode, (2) owner, or (3) group fields, which allows attackers to elevate privileges.... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2002-2360
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.... Read more
Affected Products : webmin- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-2364
Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.... Read more
Affected Products : php_ticket- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1858
Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-IN... Read more
Affected Products : application_server- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1863
Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled.... Read more
Affected Products : network_attached_storage- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-2370
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.... Read more
Affected Products : sws_simple_web_server- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1862
SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.... Read more
Affected Products : smartmail_server- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1848
TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.... Read more
Affected Products : tightvnc- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1856
HP Application Server 8.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").... Read more
Affected Products : application_server- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-1844
Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1845
Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.... Read more
Affected Products : yabb- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1842
Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address.... Read more
Affected Products : perlbot- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1841
The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.... Read more
Affected Products : nola- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-2365
Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.... Read more
Affected Products : simple_wais- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1839
Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.... Read more
Affected Products : interscan_viruswall_for_windows_nt- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1829
Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror attribute in an IMG tag (a variant of CVE-2002-0330), or ... Read more
Affected Products : openbb- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1832
Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.... Read more
Affected Products : firestorm_ids- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1837
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on... Read more
Affected Products : ids- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1944
Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.... Read more
Affected Products : surfboard- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1824
Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-t... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025