Latest CVE Feed
-
7.5
HIGHCVE-2002-0846
The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length.... Read more
Affected Products : shockwave_flash- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0411
Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.... Read more
Affected Products : aeromail- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0743
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.... Read more
Affected Products : aix- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0757
(1) Webmin 0.96 and (2) Usermin 0.90 with password timeouts enabled allow local and possibly remote attackers to bypass authentication and gain privileges via certain control characters in the authentication information, which can force Webmin or Usermin ... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2002-0430
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0466
Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathname in the filepath arguments to (1) Statsbrowse.asp, (2) servubrowse.asp, (3) browsedisk.asp, (4) browsewebalizerexe.asp, or (5) sqlbrow... Read more
Affected Products : hosting_controller- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2000-1208
Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2002-0658
OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0421
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.... Read more
Affected Products : windows_nt- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0808
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.... Read more
Affected Products : bugzilla- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0645
SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0391
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array throu... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0452
Foundry Networks ServerIron switches do not decode URIs when applying "url-map" rules, which could make it easier for attackers to cause the switch to forward traffic to a different server than intended and exploit vulnerabilities that would otherwise be ... Read more
Affected Products : serveriron- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0476
Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.... Read more
Affected Products : flash_player- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0482
Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.... Read more
Affected Products : netsupport_manager- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0496
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002.... Read more
Affected Products : southwest- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0827
Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGH- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0528
Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules.... Read more
Affected Products : soho_firewall- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0472
MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.... Read more
Affected Products : msn_messenger- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025