Latest CVE Feed
-
7.5
HIGHCVE-2002-0776
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.... Read more
Affected Products : hosting_controller- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0782
Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to hosts that do not have a specific route, which may be for... Read more
Affected Products : bordermanager- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0488
Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter.... Read more
Affected Products : linux_directory_penguin_traceroute- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0527
Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO forwards a packet with bad IP options.... Read more
Affected Products : soho_firewall- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0814
Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument.... Read more
Affected Products : gsx_server- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0774
Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed.... Read more
Affected Products : hosting_controller- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0820
FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid... Read more
Affected Products : freebsd- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0848
Cisco VPN 5000 series concentrator hardware 6.0.21.0002 and earlier, and 5.2.23.0003 and earlier, when using RADIUS with a challenge type of Password Authentication Protocol (PAP) or Challenge, sends the user password in cleartext in a validation retry re... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0770
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros... Read more
Affected Products : quake_2i_server- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-0812
Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuratio... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0795
The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files.... Read more
Affected Products : freebsd- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-0771
Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters.... Read more
Affected Products : viewcvs- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0743
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.... Read more
Affected Products : aix- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0734
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets the $b2inc variable to point to a malicious program store... Read more
Affected Products : b2- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0775
browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.... Read more
Affected Products : hosting_controller- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0733
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.... Read more
Affected Products : thttpd- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0741
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long password argument and quickly killing the connection, which is not properly terminated by psyBNC.... Read more
Affected Products : psybnc- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0744
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.... Read more
Affected Products : aix- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0815
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain nam... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0730
Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.... Read more
Affected Products : philip_chinerys_guestbook- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025