Latest CVE Feed
-
7.5
HIGHCVE-2002-0285
Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms... Read more
Affected Products : outlook_express- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0290
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.... Read more
Affected Products : webnews- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2002-0281
Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php.... Read more
Affected Products : dcp-portal- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0272
Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.... Read more
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0308
admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.... Read more
Affected Products : admentor- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0288
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.... Read more
Affected Products : phusion_webserver- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0309
SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to deter... Read more
Affected Products : enterprise_firewall- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0278
Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.... Read more
Affected Products : mailman_free- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0306
ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.... Read more
Affected Products : avengers_news_system- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-0292
Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.... Read more
Affected Products : slashcode- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0301
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.... Read more
Affected Products : nfuse- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2002-0293
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.... Read more
Affected Products : omnipcx- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0283
Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data.... Read more
Affected Products : windows_xp- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0294
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.... Read more
Affected Products : omnipcx- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0275
Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.... Read more
Affected Products : falcon_web_server- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0303
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.... Read more
Affected Products : groupwise- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0289
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.... Read more
Affected Products : phusion_webserver- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0304
Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.... Read more
Affected Products : lil_http_server- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0282
DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path... Read more
Affected Products : dcp-portal- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-0284
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.... Read more
Affected Products : winamp- Published: May. 31, 2002
- Modified: Apr. 03, 2025