Latest CVE Feed
-
7.5
HIGHCVE-2002-1350
The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).... Read more
Affected Products : tcpdump- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1643
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simu... Read more
Affected Products : helix_universal_server- Published: Dec. 19, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1159
Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1354
Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.... Read more
Affected Products : typsoft_ftp_server- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1340
The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception.... Read more
Affected Products : office_web_components- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2002-1347
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during ... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1338
The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.... Read more
Affected Products : office_web_components- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1339
The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.... Read more
Affected Products : office_web_components- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1341
Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1342
Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.... Read more
Affected Products : smb2www- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1255
Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 20... Read more
Affected Products : outlook- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1262
Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files.... Read more
Affected Products : internet_explorer- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1349
Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1344
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.... Read more
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1158
Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.... Read more
Affected Products : canna- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1317
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1185
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during de... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1266
Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File."... Read more
Affected Products : mac_os_x- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1268
Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."... Read more
Affected Products : mac_os_x- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1254
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via C... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025