Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0302
The Notify daemon for Symantec Enterprise Firewall (SEF) 6.5.x drops large alerts when SNMP is used as the transport, which could prevent some alerts from being sent in the event of an attack.... Read more
Affected Products : enterprise_firewall- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0272
Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.... Read more
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0305
Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge.... Read more
Affected Products : p100s- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0286
The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produ... Read more
Affected Products : sitenews- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0289
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.... Read more
Affected Products : phusion_webserver- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0278
Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.... Read more
Affected Products : mailman_free- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0308
admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.... Read more
Affected Products : admentor- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0288
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.... Read more
Affected Products : phusion_webserver- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0306
ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.... Read more
Affected Products : avengers_news_system- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2002-0293
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.... Read more
Affected Products : omnipcx- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0301
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.... Read more
Affected Products : nfuse- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0303
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.... Read more
Affected Products : groupwise- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0275
Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.... Read more
Affected Products : falcon_web_server- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0309
SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to deter... Read more
Affected Products : enterprise_firewall- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0294
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.... Read more
Affected Products : omnipcx- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0283
Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data.... Read more
Affected Products : windows_xp- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0304
Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.... Read more
Affected Products : lil_http_server- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0290
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.... Read more
Affected Products : webnews- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0280
Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply.... Read more
Affected Products : codeblue- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2002-0281
Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php.... Read more
Affected Products : dcp-portal- Published: May. 31, 2002
- Modified: Apr. 03, 2025