Latest CVE Feed
-
4.6
MEDIUMCVE-2002-1266
Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File."... Read more
Affected Products : mac_os_x- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1318
Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a lit... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1188
Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, a... Read more
Affected Products : internet_explorer- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1187
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as ... Read more
Affected Products : internet_explorer- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1336
TightVNC before 1.2.6 generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1320
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").... Read more
Affected Products : pine- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1185
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during de... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1319
The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1587
The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.... Read more
- Published: Dec. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1586
Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.... Read more
- Published: Dec. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1588
Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2 allows remote attackers to cause a denial of service (mailtool segmentation violation and crash) via a malformed mail attachment.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1219
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1276
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1288
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1287
Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1221
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1220
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1291
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1295
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private c... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1285
runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.... Read more
Affected Products : suse_linux- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025