Latest CVE Feed
-
7.5
HIGHCVE-2002-0916
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not prope... Read more
Affected Products : msntauth- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1072
ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.... Read more
Affected Products : prestige- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0876
Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.... Read more
Affected Products : shambala_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1067
Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buffer overflow.... Read more
Affected Products : ic9_pocket_print_server_firmware- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0879
showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.... Read more
Affected Products : cfximage- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1081
The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.... Read more
Affected Products : abyss_web_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0931
Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" paramet... Read more
Affected Products : myhelpdesk- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1097
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1053
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error... Read more
Affected Products : jigsaw- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0909
Multiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local users can gain privileges via long command line arguments (2) -f, (3) -n, (4) -D, (5) -M, or (6) -P, or via long envi... Read more
Affected Products : mnews- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1065
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing.... Read more
Affected Products : jana_web_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0889
Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a long bulldir argument in the user's .qpopper-options configuration file.... Read more
Affected Products : qpopper- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1042
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in ... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1068
The web server for D-Link DP-300 print server allows remote attackers to cause a denial of service (hang) via a large HTTP POST request.... Read more
Affected Products : dp-303- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1082
The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.... Read more
Affected Products : ezcontents- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0930
Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command.... Read more
Affected Products : netware- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0906
Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.... Read more
Affected Products : sendmail- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0918
CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter,... Read more
Affected Products : cspassword- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1047
The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name.... Read more
Affected Products : soho_firewall- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1054
Directory traversal vulnerability in Pablo FTP server 1.0 build 9 and earlier allows remote authenticated users to list arbitrary directories via "..\" (dot-dot backslash) sequences in a LIST command.... Read more
Affected Products : pablo_ftp_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025