Latest CVE Feed
-
10.0
HIGHCVE-2002-1226
Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).... Read more
Affected Products : heimdal- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1228
Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1202
Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.... Read more
Affected Products : tru64- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1118
TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1195
Cross-site scripting vulnerability (XSS) in the PHP interface for ht://Check 1.1 allows remote web servers to insert arbitrary HTML, including script, via a web page.... Read more
Affected Products : ht_check- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1197
bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.... Read more
Affected Products : bugzilla- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1203
IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any fl... Read more
Affected Products : secureway_firewall- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1213
Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward sl... Read more
Affected Products : webserver_4_all- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1179
Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or preview... Read more
Affected Products : outlook_express- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1201
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.... Read more
Affected Products : aix- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1200
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a... Read more
Affected Products : syslog-ng- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1145
The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updati... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0836
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1229
Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1199
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1227
PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.... Read more
Affected Products : pam- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1217
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document ... Read more
Affected Products : internet_explorer- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1212
Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.... Read more
Affected Products : webserver_4_all- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1190
Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.... Read more
Affected Products : unity_server- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2002-1222
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.... Read more
Affected Products : catos- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025