Latest CVE Feed
-
7.5
HIGHCVE-2002-1123
Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.... Read more
- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0724
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2... Read more
- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0834
Buffer overflow in the ISIS dissector for Ethereal 0.9.5 and earlier allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.... Read more
- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-1126
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, includin... Read more
- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0648
The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.... Read more
Affected Products : internet_explorer- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0974
Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm.... Read more
Affected Products : windows_xp- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0970
The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.... Read more
- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1612
Buffer overflow in mailcv in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.... Read more
- Published: Sep. 13, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1615
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader.... Read more
- Published: Sep. 13, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1613
Buffer overflow in ps in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.... Read more
- Published: Sep. 10, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1614
Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.... Read more
- Published: Sep. 09, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0851
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a cal... Read more
Affected Products : isdn4linux- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0872
l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.... Read more
Affected Products : l2tpd- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0856
SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.... Read more
- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0853
Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a zero-length payload.... Read more
Affected Products : vpn_client- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0720
A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.... Read more
- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0721
Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator pri... Read more
- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0855
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.... Read more
Affected Products : mailman- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0874
Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.... Read more
Affected Products : interchange- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0093
Buffer overflow in ipcs for HP Tru64 UNIX 4.0f through 5.1a may allow attackers to execute arbitrary code, a different vulnerability than CVE-2001-0423.... Read more
Affected Products : tru64- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025