Latest CVE Feed
-
2.1
LOWCVE-2002-1193
tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.... Read more
Affected Products : tkmail- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1225
Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.... Read more
Affected Products : heimdal- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1216
GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.... Read more
Affected Products : tar- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1201
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.... Read more
Affected Products : aix- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1179
Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or preview... Read more
Affected Products : outlook_express- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1589
Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of service (system panic).... Read more
- Published: Oct. 24, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1451
Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT request... Read more
Affected Products : windows_2000- Published: Oct. 22, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1618
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.... Read more
- Published: Oct. 16, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1150
The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL... Read more
Affected Products : netmeeting- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0866
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc wi... Read more
Affected Products : virtual_machine- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1170
The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1189
The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.... Read more
Affected Products : unity_server- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1141
An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "D... Read more
Affected Products : services- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0839
The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that woul... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0843
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1146
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read pas... Read more
Affected Products : glibc- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-0840
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page vis... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0969
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Ful... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1166
Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request.... Read more
Affected Products : wn_server- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0864
The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of S... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025