Latest CVE Feed
-
7.5
HIGHCVE-2002-1190
Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.... Read more
Affected Products : unity_server- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1199
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2002-1222
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.... Read more
Affected Products : catos- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1227
PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.... Read more
Affected Products : pam- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1229
Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0836
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.... Read more
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1198
Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.... Read more
Affected Products : bugzilla- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1200
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a... Read more
Affected Products : syslog-ng- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1196
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to user... Read more
Affected Products : bugzilla- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1194
Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.... Read more
Affected Products : netbsd- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1191
The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.... Read more
Affected Products : desktop_reservation_software- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1589
Unknown vulnerability in Solaris 8, when the 0x02 bit (aka TEST, KMF_DEADBEEF, or deadbeef) is set in the kmem_flags kernel parameter, allows local users to cause a denial of service (system panic).... Read more
- Published: Oct. 24, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1451
Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT request... Read more
Affected Products : windows_2000- Published: Oct. 22, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1618
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.... Read more
- Published: Oct. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0866
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc wi... Read more
Affected Products : virtual_machine- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1137
Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a lon... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0863
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Wea... Read more
Affected Products : windows_2000 windows_xp windows_nt windows_2000_terminal_services .net_windows_server- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1170
The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.... Read more
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1150
The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL... Read more
Affected Products : netmeeting- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1140
The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size chec... Read more
Affected Products : services- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025