Latest CVE Feed
-
7.5
HIGHCVE-2002-1142
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stu... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1204
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing... Read more
Affected Products : communicator- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1288
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call.... Read more
Affected Products : java_virtual_machine- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1644
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to remove the child process from the process group of the parent process, which allows attackers to gain certain priv... Read more
Affected Products : ssh2- Published: Nov. 25, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1645
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL.... Read more
Affected Products : ssh2- Published: Nov. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1312
Buffer overflow in the Web management interface in Linksys BEFW11S4 wireless access point router 2 and BEFSR11, BEFSR41, and BEFSRU31 EtherFast Cable/DSL routers with firmware before 1.43.3 with remote management enabled allows remote attackers to cause a... Read more
- Published: Nov. 20, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1250
Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument.... Read more
Affected Products : abuse- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1251
Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message.... Read more
Affected Products : log2mail- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1239
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.... Read more
Affected Products : rtos- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1242
SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.... Read more
Affected Products : php-nuke- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0711
Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.... Read more
Affected Products : trucluster_server- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1245
Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program.... Read more
Affected Products : luxman- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1248
Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) via a GET request for a "%" URI.... Read more
Affected Products : xeneo_web_server- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1244
Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.... Read more
Affected Products : pablo_ftp_server- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1181
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP ... Read more
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1211
Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.... Read more
Affected Products : prometheus- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0869
Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out... Read more
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1278
The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail rel... Read more
Affected Products : linuxconf- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1180
A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vuln... Read more
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1277
Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer.... Read more
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025