Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2332 1 Opera Software 1 Opera Web Browser 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in Opera 6.01 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attributes.
CVE-2002-2333 1 Kde 1 Kde 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in konqueror in KDE 2.1 through 3.0 and 3.0.2 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height attributes.
CVE-2002-2334 1 Joseph Allen 1 Joe 2008-09-05 3.6 LOW N/A
Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.
CVE-2002-2335 1 John Drake 1 Killer Protection 2008-09-05 5.0 MEDIUM N/A
Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.
CVE-2002-2336 1 Symantec 1 Norton Personal Firewall 2008-09-05 4.3 MEDIUM N/A
Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
CVE-2002-2337 1 Kaspersky Lab 1 Kaspersky Anti-hacker 2008-09-05 5.0 MEDIUM N/A
Kaspersky Anti-Hacker 1.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
CVE-2002-2338 2 Mozilla, Netscape 3 Mozilla, Communicator, Navigator 2008-09-05 5.0 MEDIUM N/A
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
CVE-2002-2339 1 Script Shed 1 Ssgbook 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in (1) image, (2) img, (3) image=right, (4) img=right, (5) image=left, and (6) img=left tags.
CVE-2002-2018 1 Sas 2 Base, Integration Technologies 2008-09-05 7.2 HIGH N/A
sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.
CVE-2002-2345 1 Oracle 1 Application Server 2008-09-05 7.5 HIGH N/A
Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.
CVE-2002-2346 1 Phpbb 1 Phpbb 2008-09-05 5.0 MEDIUM N/A
phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.
CVE-2002-2347 1 Oracle 1 Application Server 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field.
CVE-2002-2348 1 Authoria 1 Authoria 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web script or HTML via the command parameter.
CVE-2002-2016 1 User-mode Linux 1 User-mode Linux 2008-09-05 7.2 HIGH N/A
User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code.
CVE-2002-2172 1 Shana 2 Informed Designer, Informed Filler 2008-09-05 2.1 LOW N/A
Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information.
CVE-2002-2178 1 Phpwebsite 1 Phpwebsite 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag.
CVE-2002-2170 1 Working Resources Inc. 1 Badblue 2008-09-05 7.5 HIGH N/A
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.
CVE-2002-2169 1 Aol 1 Instant Messenger 2008-09-05 5.0 MEDIUM N/A
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.
CVE-2002-2168 1 Thorsten Korner 1 123tkshop 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php.
CVE-2002-2179 1 Unisys 1 Clearpath Mcp 2008-09-05 7.8 HIGH N/A
The dynamic initialization feature of the ClearPath MCP environment allows remote attackers to cause a denial of service (crash) via a TCP port scan using a tool such as nmap.
CVE-2002-2158 1 Zendocs 1 Zentrack 2008-09-05 5.0 MEDIUM N/A
zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message.
CVE-2002-2156 1 Cerulean Studios 1 Trillian 2008-09-05 7.5 HIGH N/A
Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response.
CVE-2002-2310 1 Kryptronic 1 Clickcartpro 2008-09-05 5.0 MEDIUM N/A
ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
CVE-2002-2155 1 Cerulean Studios 1 Trillian 2008-09-05 7.5 HIGH N/A
Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string specifiers in the name.
CVE-2002-2309 1 Php 1 Php 2008-09-05 7.8 HIGH N/A
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
CVE-2002-2180 1 Openbsd 1 Openbsd 2008-09-05 6.8 MEDIUM N/A
The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via an integer signedness error.
CVE-2002-2144 1 Free Peers 1 Bearshare 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in BearShare 4.0.5 and 4.0.6 allows remote attackers to read files outside of the web root by hex-encoding the "/" (forward slash) or "." (dot) characters.
CVE-2002-2143 1 Mysimplenews 1 Mysimplenews 2008-09-05 7.5 HIGH N/A
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.
CVE-2002-2181 1 Sonicwall 1 Content Filtering 2008-09-05 5.0 MEDIUM N/A
SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.
CVE-2002-2182 1 Seunghyun Seo 1 Msn666 2008-09-05 6.4 MEDIUM N/A
Buffer overflow in Seunghyun Seo's MSN666 MSN Sniffer 1.0 and 1.0.1 allows remote attackers to execute arbitrary code via a long MSN packet.
CVE-2002-2146 1 Savant 1 Savant Webserver 2008-09-05 7.5 HIGH N/A
cgitest.exe in Savant Web Server 3.1 and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request.
CVE-2002-2128 1 W-agora 1 W-agora 2008-09-05 4.6 MEDIUM N/A
editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. (dot dot) sequences in the file parameter.
CVE-2002-2308 1 Netscape 1 Communicator 2008-09-05 5.0 MEDIUM N/A
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself.
CVE-2002-2126 1 Pedestal Software 1 Integrity Protection Driver 2008-09-05 2.1 LOW N/A
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.
CVE-2002-2195 1 Nullsoft 1 Winamp 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.
CVE-2002-2120 1 Qnx 1 Rtos 2008-09-05 4.6 MEDIUM N/A
Multiple buffer overflows in QNX RTOS 4.25 may allow attackers to execute arbitrary code via long filename arguments to (1) Watcom or (2) int10.
CVE-2002-2119 1 Novell 1 Edirectory 2008-09-05 7.5 HIGH N/A
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.
CVE-2002-2196 1 Samba 1 Samba 2008-09-05 7.5 HIGH N/A
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
CVE-2002-2117 1 Microsoft 1 Windows Xp 2008-09-05 5.0 MEDIUM N/A
Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP).
CVE-2002-2307 1 Pyramid 1 Benhur Software Update 2008-09-05 5.0 MEDIUM N/A
The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20.
CVE-2002-2116 1 Netgear 2 Rm356, Rt338 2008-09-05 5.0 MEDIUM N/A
Netgear RM-356 and RT-338 series SOHO routers allow remote attackers to cause a denial of service (crash) via a UDP port scan, as demonstrated using nmap.
CVE-2002-2110 1 Rca 1 Digital Cable Modem 2008-09-05 5.0 MEDIUM N/A
The RCA Digital Cable Modems DCM225 and DCM225E allow remote attackers to cause a denial of service (modem device reset) by connecting to port 80 on the 10.0.0.0/8 device.
CVE-2002-2109 1 Matt Wright 1 Formmail 2008-09-05 7.5 HIGH N/A
Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.
CVE-2002-2108 1 Sony 1 Vaio Manual Cybersupport 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in the "VAIO Manual" software in certain Sony VAIO personal computers sold from November 2001 to January 2002, allows remote attackers to modify data via a web page or HTML e-mail.
CVE-2002-2107 1 Veridis 1 Openkeyserver 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the lookup script in Veridis OpenKeyServer (OKS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CVE-2002-2101 1 Microsoft 1 Outlook 2008-09-05 7.5 HIGH N/A
Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
CVE-2002-2100 1 Microsoft 1 Outlook 2008-09-05 5.0 MEDIUM N/A
Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
CVE-2002-2198 1 Zmailer 1 Zmailer 2008-09-05 10.0 HIGH N/A
Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing from an IPv6 address, possibly using an address that resolves to a long hostname.
CVE-2002-2096 1 Novell 1 Netware 2008-09-05 7.5 HIGH N/A
Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary code via a long (1) username or (2) password.
CVE-2002-2090 1 Caucho Technology 1 Resin 2008-09-05 5.0 MEDIUM N/A
Caucho Technology Resin server 2.1.1 to 2.1.2 allows remote attackers to obtain server's root path via requests for MS-DOS device names such as lpt9.xtp.