Latest CVE Feed
-
7.5
HIGHCVE-2002-1368
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Con... Read more
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1385
openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuratio... Read more
Affected Products : open_webmail- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1372
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to... Read more
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1371
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.... Read more
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1351
Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) ... Read more
Affected Products : melange_chat_system- Published: Dec. 24, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1381
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.... Read more
Affected Products : exim- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1350
The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).... Read more
Affected Products : tcpdump- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1380
Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1257
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.... Read more
Affected Products : windows_2000 windows_xp windows_95 windows_98 windows_nt windows_98se windows_me windows_2000_terminal_services- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1382
Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846.... Read more
Affected Products : flash_player- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1375
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1377
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.... Read more
Affected Products : vim- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1296
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1258
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the ... Read more
Affected Products : windows_2000 windows_xp windows_95 windows_98 windows_nt windows_98se windows_me windows_2000_terminal_services- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1325
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."... Read more
Affected Products : windows_2000 windows_xp windows_95 windows_98 windows_nt windows_98se windows_me windows_2000_terminal_services- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1357
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH prot... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1365
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local address... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1373
Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.... Read more
Affected Products : mysql- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1361
overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.... Read more
Affected Products : cobalt_raq_4- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1362
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025