Latest CVE Feed
-
10.0
HIGHCVE-2002-0640
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (... Read more
Affected Products : openssh- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0372
Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored... Read more
Affected Products : windows_media_player- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0574
Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which preven... Read more
Affected Products : freebsd- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0621
Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package... Read more
Affected Products : commerce_server- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0623
Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".... Read more
Affected Products : commerce_server- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0540
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.... Read more
Affected Products : cvx_1800_multi-service_access_switch- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0553
Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.... Read more
Affected Products : sunshop_shopping_cart- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0537
The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.... Read more
Affected Products : sws- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0187
Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."... Read more
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0561
The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings.... Read more
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0564
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.... Read more
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0334
xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows local users to modify files via a symlink attack on the .xtell-log file.... Read more
Affected Products : xtell- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0346
Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0349
Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions.... Read more
Affected Products : tiny_personal_firewall- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0321
Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.... Read more
Affected Products : messenger- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1300
Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.... Read more
Affected Products : dynu_ftp_server- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0339
Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.... Read more
Affected Products : ios- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0347
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0319
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.... Read more
Affected Products : pforum- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0006
XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the ... Read more
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025