Latest CVE Feed
-
7.5
HIGHCVE-2002-0836
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1145
The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updati... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1200
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a... Read more
Affected Products : syslog-ng- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1201
IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.... Read more
Affected Products : aix- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1179
Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or preview... Read more
Affected Products : outlook_express- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1202
Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.... Read more
Affected Products : tru64- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1589
Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of service (system panic).... Read more
- Published: Oct. 24, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1451
Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT request... Read more
Affected Products : windows_2000- Published: Oct. 22, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1618
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.... Read more
- Published: Oct. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0866
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc wi... Read more
Affected Products : virtual_machine- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1170
The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1150
The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL... Read more
Affected Products : netmeeting- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1178
Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.... Read more
Affected Products : jetty_http_server- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0863
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Wea... Read more
Affected Products : windows_2000 windows_xp windows_nt windows_2000_terminal_services .net_windows_server- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2002-1147
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of servic... Read more
Affected Products : procurve_switch_4000m- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1152
Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing.... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-0840
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page vis... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1165
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1153
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".... Read more
Affected Products : websphere_application_server- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1138
Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overw... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025