Latest CVE Feed
-
7.5
HIGHCVE-2002-1371
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.... Read more
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1369
jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1383
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as ... Read more
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1177
Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.... Read more
Affected Products : winamp- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1327
Buffer overflow in the Windows Shell function in Microsoft Windows XP allows remote attackers to execute arbitrary code via an .MP3 or .WMA audio file with a corrupt custom attribute, aka "Unchecked Buffer in Windows Shell Could Enable System Compromise."... Read more
Affected Products : windows_xp- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1176
Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.... Read more
Affected Products : winamp- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1385
openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuratio... Read more
Affected Products : open_webmail- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1363
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.... Read more
Affected Products : libpng- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1351
Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) ... Read more
Affected Products : melange_chat_system- Published: Dec. 24, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1381
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.... Read more
Affected Products : exim- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1345
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1355
Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1358
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1350
The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).... Read more
Affected Products : tcpdump- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1362
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1360
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to ... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1374
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first c... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1356
Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1365
Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local address... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1382
Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846.... Read more
Affected Products : flash_player- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025