Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0438
ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall's IP address and an incorrect MAC address, which causes the firewall to disable the LAN interface.... Read more
Affected Products : zywall10- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0408
htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard... Read more
Affected Products : domino- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0443
Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.... Read more
Affected Products : windows_2000- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0450
Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe.... Read more
Affected Products : web\+_server- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0405
Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters.... Read more
Affected Products : broker_ftp_server- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0440
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header set to 0, which is often ignored by HTTP clients.... Read more
Affected Products : interscan_viruswall- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0717
PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and... Read more
Affected Products : php- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1599
DansGuardian before 2.4.5-1 allows remote attackers to bypass content filtering rules via hex-encoded URLs.... Read more
Affected Products : dansguardian- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0670
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.... Read more
Affected Products : xpressa- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0668
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and hijack calls.... Read more
Affected Products : xpressa- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0687
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.... Read more
Affected Products : zope- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0683
Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.... Read more
Affected Products : carello- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0701
ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was runni... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0680
Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been r... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0672
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null.... Read more
Affected Products : xpressa- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0642
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permissio... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0674
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication.... Read more
Affected Products : xpressa- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0681
Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.... Read more
Affected Products : goahead_webserver- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0624
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, ... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.... Read more
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025