Latest CVE Feed
-
4.6
MEDIUMCVE-2002-0358
MediaMail and MediaMail Pro in SGI IRIX 6.5.16 and earlier allows local users to force the program to dump core via certain arguments, which could allow the users to read sensitive data or gain privileges.... Read more
Affected Products : mediamail- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0444
Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of lic... Read more
Affected Products : windows_2000_terminal_services- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0441
Directory traversal vulnerability in imlist.php for Php Imglist allows remote attackers to read arbitrary code via a .. (dot dot) in the cwd parameter.... Read more
Affected Products : php_imglist- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0410
send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.... Read more
Affected Products : aeromail- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0438
ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall's IP address and an incorrect MAC address, which causes the firewall to disable the LAN interface.... Read more
Affected Products : zywall10- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0393
Buffer overflow in Red-M 1050 (Bluetooth Access Point) management web interface allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long administration password.... Read more
Affected Products : 1050ap_lan_acess_point- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0713
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (... Read more
Affected Products : squid- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0714
FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.... Read more
Affected Products : squid- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0715
Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.... Read more
Affected Products : squid- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0433
Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.... Read more
Affected Products : pi3web- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0436
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.... Read more
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0702
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS serve... Read more
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0624
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, ... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0668
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and hijack calls.... Read more
Affected Products : xpressa- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0687
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.... Read more
Affected Products : zope- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1599
DansGuardian before 2.4.5-1 allows remote attackers to bypass content filtering rules via hex-encoded URLs.... Read more
Affected Products : dansguardian- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0670
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.... Read more
Affected Products : xpressa- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0673
The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In to gain remote access and perfo... Read more
Affected Products : xpressa- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0682
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.... Read more
Affected Products : tomcat- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0667
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.... Read more
Affected Products : xpressa- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025