Latest CVE Feed
-
7.5
HIGHCVE-2002-0906
Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.... Read more
Affected Products : sendmail- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0899
Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot).... Read more
Affected Products : falcon_web_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0914
Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop.... Read more
Affected Products : courier_mta- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0909
Multiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local users can gain privileges via long command line arguments (2) -f, (3) -n, (4) -D, (5) -M, or (6) -P, or via long envi... Read more
Affected Products : mnews- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1059
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string.... Read more
Affected Products : securecrt- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0954
The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make it easier for an attacker to decrypt the passwords using brute force techniques.... Read more
Affected Products : pix_firewall- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1040
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.... Read more
Affected Products : aix- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1107
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing.... Read more
Affected Products : vpn_client- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0904
SayText function in Kismet 2.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters (backtick or pipe) in the essid argument.... Read more
Affected Products : kismet- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1027
Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.... Read more
Affected Products : sitespring- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1062
Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.... Read more
Affected Products : jana_web_server- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0896
The throttle capability in Swatch may fail to report certain events if (1) the same type of event occurs after the throttle period, or (2) when multiple events matching the same "watchfor" expression do not occur after the throttle period, which could all... Read more
Affected Products : swatch- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0951
SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password.... Read more
Affected Products : body_builder- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1133
Encoded directory traversal vulnerability in Dino's web server 2.1 allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "\" (%5c) characters.... Read more
Affected Products : dinos_webserver- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1108
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.... Read more
Affected Products : vpn_client- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0936
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).... Read more
Affected Products : tomcat- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0959
Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script.... Read more
Affected Products : splatt_forum- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1044
Buffer overflow in Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Subject field.... Read more
Affected Products : popcorn- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1037
Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Dep... Read more
Affected Products : double_choco_latte- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1083
Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file list... Read more
Affected Products : ezcontents- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025