Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0209
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with a half-closed session, which causes ACEdirector to send ... Read more
Affected Products : alteon_acedirector- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0172
/dev/ipfilter on SGI IRIX 6.5 is installed by /dev/MAKEDEV with insecure default permissions (644), which could allow a local user to cause a denial of service (traffic disruption).... Read more
Affected Products : irix- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0157
Nautilus 1.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the .nautilus-metafile.xml metadata file.... Read more
Affected Products : nautilus- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0199
Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes.... Read more
Affected Products : shoutcast_server- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0171
IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges.... Read more
Affected Products : irisconsole- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0207
Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds the actual length of the header.... Read more
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0221
Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV.... Read more
Affected Products : eserv- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0203
ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.... Read more
Affected Products : tarantella_enterprise- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0198
Buffer overflow in plDaniels ripMime 1.2.6 and earlier, as used in other programs such as xamime and inflex, allows remote attackers to execute arbitrary code via an attachment in a long filename.... Read more
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0213
xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.... Read more
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0220
phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters.... Read more
Affected Products : phpsmssend- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0226
retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.... Read more
Affected Products : dcforum- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0201
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.... Read more
Affected Products : cyberstop_web_server- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0218
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.... Read more
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0212
The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernames and makes it easier to conduct a brute force attack.... Read more
Affected Products : hosting_controller- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0227
KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.... Read more
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0200
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.... Read more
Affected Products : cyberstop_web_server- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0206
index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.... Read more
Affected Products : php-nuke- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0217
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.... Read more
Affected Products : xoops- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1592
The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : http_server- Published: May. 06, 2002
- Modified: Apr. 03, 2025