Latest CVE Feed
-
7.5
HIGHCVE-2002-0692
Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file r... Read more
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0705
The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.... Read more
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1105
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password.... Read more
Affected Products : vpn_client- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0887
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.... Read more
Affected Products : openserver- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2002-0920
CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been p... Read more
Affected Products : cspassword- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-0932
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) update... Read more
Affected Products : myhelpdesk- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0948
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.... Read more
Affected Products : makebook- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1000
Buffer overflow in AnalogX SimpleServer:Shout 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long request to TCP port 8001.... Read more
Affected Products : simpleserver_shout- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0998
Directory traversal vulnerability in cafenews.php for CARE 2002 before beta 1.0.02 allows remote attackers to read arbitrary files via .. (dot dot) sequences and null characters in the lang parameter, which is processed by a call to the include function.... Read more
Affected Products : care_2002- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1070
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.... Read more
Affected Products : php-wiki- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1064
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.... Read more
Affected Products : jana_web_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1084
The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.... Read more
Affected Products : ezcontents- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1076
Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.... Read more
Affected Products : imail- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1032
Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.... Read more
Affected Products : kf_web_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1031
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.... Read more
Affected Products : kf_web_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0940
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module pr... Read more
Affected Products : mscapi_csp- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0900
Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long search argument to the lookup capability.... Read more
Affected Products : pgp_public_key_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1028
Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash) via long arguments.... Read more
Affected Products : song_requester- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0923
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.... Read more
Affected Products : csnews- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1089
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025