Latest CVE Feed
-
6.8
MEDIUMCVE-2002-1334
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.... Read more
Affected Products : imagefolio- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1186
Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1335
Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.... Read more
Affected Products : w3m- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1323
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.... Read more
Affected Products : enterprise_linux solaris sunos unixware linux_advanced_workstation irix open_unix safe.pm linux- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1270
Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call.... Read more
Affected Products : mac_os_x- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1266
Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File."... Read more
Affected Products : mac_os_x- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1268
Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."... Read more
Affected Products : mac_os_x- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1317
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1183
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1319
The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1187
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as ... Read more
Affected Products : internet_explorer- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1188
Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, a... Read more
Affected Products : internet_explorer- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1321
Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u ... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1185
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during de... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1336
TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1320
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").... Read more
Affected Products : pine- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1254
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via C... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1587
The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.... Read more
- Published: Dec. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1586
Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.... Read more
- Published: Dec. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1295
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private c... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025