Latest CVE Feed
-
7.5
HIGHCVE-2002-0348
service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0335
Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request.... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0354
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result us... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0328
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.... Read more
Affected Products : ikonboard- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0343
Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.... Read more
Affected Products : hotline_connect- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0350
HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service.... Read more
Affected Products : procurve_switch_4000m- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0360
Buffer overflow in Sun AnswerBook2 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long filename argument to the gettransbitmap CGI program.... Read more
Affected Products : solaris_answerbook2- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0329
Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag.... Read more
Affected Products : snitz_forums_2000- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0330
Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag.... Read more
Affected Products : openbb- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0381
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadca... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0346
Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0334
xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows local users to modify files via a symlink attack on the .xtell-log file.... Read more
Affected Products : xtell- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0333
Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument.... Read more
Affected Products : xtell- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0353
The ASN.1 parser in Ethereal 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a certain malformed packet, which causes Ethereal to allocate memory incorrectly, possibly due to zero-length fields.... Read more
Affected Products : ethereal- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0322
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.... Read more
Affected Products : messenger- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0332
Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostname that is determined using reverse DNS lookups, (2) a long AUTH string, or (3) certain data in the xtell... Read more
Affected Products : xtell- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0320
Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field.... Read more
Affected Products : messenger- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0345
Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.... Read more
Affected Products : norton_ghost- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0324
Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password ... Read more
Affected Products : graymatter- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0336
Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025