Latest CVE Feed
-
4.6
MEDIUMCVE-2002-0643
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encr... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0641
Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT que... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0642
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permissio... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0624
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, ... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0653
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entrie... Read more
Affected Products : mod_ssl- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0676
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and s... Read more
Affected Products : mac_os_x- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0665
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.... Read more
Affected Products : jrun- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0637
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Typ... Read more
Affected Products : interscan_viruswall- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1448
An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.... Read more
- Published: Jul. 08, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0622
The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".... Read more
Affected Products : commerce_server- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0541
Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HT... Read more
Affected Products : tivoli_storage_manager- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0557
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrec... Read more
Affected Products : openbsd- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0549
Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users.... Read more
Affected Products : anthill- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0556
Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.... Read more
Affected Products : quik-serv_webserver- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0621
Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package... Read more
Affected Products : commerce_server- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0623
Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".... Read more
Affected Products : commerce_server- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0574
Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which preven... Read more
Affected Products : freebsd- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0553
Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.... Read more
Affected Products : sunshop_shopping_cart- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0540
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.... Read more
Affected Products : cvx_1800_multi-service_access_switch- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0372
Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored... Read more
Affected Products : windows_media_player- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025