Latest CVE Feed
-
7.2
HIGHCVE-2002-1239
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.... Read more
Affected Products : rtos- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1251
Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message.... Read more
Affected Products : log2mail- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1181
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP ... Read more
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1184
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to g... Read more
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0711
Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.... Read more
Affected Products : trucluster_server- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1253
Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.... Read more
Affected Products : abuse- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1238
Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.... Read more
Affected Products : simple_web_server- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1275
Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."... Read more
Affected Products : html2ps- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1264
Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.... Read more
Affected Products : oracle9i- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1277
Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer.... Read more
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1211
Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.... Read more
Affected Products : prometheus- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1236
The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.... Read more
Affected Products : befsr41- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1265
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).... Read more
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1271
The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the mail body, which is then processed by mailx.... Read more
Affected Products : perl-mailtools- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1585
Unknown vulnerability in Solaris 8 for Intel and Solaris 8 and 9 for SPARC allows remote attackers to cause a denial of service via certain packets that cause some network interfaces to stop responding to TCP traffic.... Read more
- Published: Nov. 08, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0666
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packe... Read more
Affected Products : aix freebsd mac_os_x mac_os_x_server netbsd frees_wan gnat_box_firmware bluefire_ix1035_router ix1010 ix1011 +3 more products- Published: Nov. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1232
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.... Read more
- Published: Nov. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1209
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.... Read more
Affected Products : tftp_server- Published: Nov. 04, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1167
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.... Read more
Affected Products : websphere_caching_proxy_server- Published: Nov. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1157
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on ... Read more
Affected Products : mod_ssl- Published: Nov. 04, 2002
- Modified: Apr. 03, 2025