Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2163 1 Killervault 1 Kvpoll 2008-09-05 4.0 MEDIUM N/A
KvPoll 1.1 allows remote authenticated users to vote more than once by setting the "already_voted" cookie by various methods, including a direct call to clear_cookies.php.
CVE-2002-2037 1 Cisco 5 Bams, Pgw 2200, Sc2200 and 2 more 2008-09-05 5.0 MEDIUM N/A
The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris 2.6 with unnecessary services and without the latest security patches, which allows attackers to exploit known vulnerabilities.
CVE-2002-2164 1 Microsoft 1 Outlook Express 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.
CVE-2002-2165 1 Imho 1 Imho Webmail 2008-09-05 2.1 LOW N/A
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.
CVE-2002-2166 1 E-zone Media Inc. 1 Fusetalk 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script.
CVE-2002-2095 1 Joe Testa 1 Hellbent 2008-09-05 5.0 MEDIUM N/A
Joe Testa hellbent 01 webserver allows attackers to read files that are specified in the hellbent.prefs file by creating a file with a similar name in the web root, as demonstrated using (1) index.webroot and (2) index.ipallow.
CVE-2002-2094 1 Joe Testa 1 Hellbent 2008-09-05 5.0 MEDIUM N/A
Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root's parent, which generates a 403 error message if the parent is incorrect, but a normal response if the parent is correct.
CVE-2002-2168 1 Thorsten Korner 1 123tkshop 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php.
CVE-2002-2091 1 Decfingerd 1 Decfingerd 2008-09-05 7.5 HIGH N/A
Format string vulnerability in Deception Finger Daemon, decfingerd, 0.7 may allow remote attackers to execute arbitrary code via the username of a finger request.
CVE-2002-2169 1 Aol 1 Instant Messenger 2008-09-05 5.0 MEDIUM N/A
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.
CVE-2002-2090 1 Caucho Technology 1 Resin 2008-09-05 5.0 MEDIUM N/A
Caucho Technology Resin server 2.1.1 to 2.1.2 allows remote attackers to obtain server's root path via requests for MS-DOS device names such as lpt9.xtp.
CVE-2002-2089 1 Sun 1 Solaris 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.
CVE-2002-2170 1 Working Resources Inc. 1 Badblue 2008-09-05 7.5 HIGH N/A
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.
CVE-2002-2088 1 Mosix Project 1 Clump Os 2008-09-05 10.0 HIGH N/A
The MOSIX Project clump/os 5.4 creates a default VNC account without a password, which allows remote attackers to gain root access.
CVE-2002-2087 1 Borland Software 1 Interbase 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_drop, (2) gds_lock_mgr, or (3) gds_inet_server.
CVE-2002-2085 1 Wwwebbb 1 Wwwebbb Forum 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in page.cgi of WWWeBBB Forum 3.82 beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.
CVE-2002-2172 1 Shana 2 Informed Designer, Informed Filler 2008-09-05 2.1 LOW N/A
Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information.
CVE-2002-2084 1 Portix-php 1 Portix-php 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) l and (2) topic parameters.
CVE-2002-2083 1 Novell 1 Netware 2008-09-05 2.1 LOW N/A
The Novell Netware client running on Windows 95 allows local users to bypass the login and open arbitrary files via the "What is this?" help feature, which can be launched from the Novell Netware login screen.
CVE-2002-1977 1 Pgp 1 Pgp 2008-09-05 2.1 LOW N/A
Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.
CVE-2002-1981 1 Microsoft 1 Sql Server 2008-09-05 5.0 MEDIUM N/A
Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
CVE-2002-2082 1 Floosietek 2 Ftgateoffice, Ftgatepro 2008-09-05 7.5 HIGH N/A
FTGate and FTGate Pro 1.05 lock user mailboxes before authentication succeeds, which allows remote attackers to lock the mailboxes of other users.
CVE-2002-2205 1 Webresolve 1 Webresolve 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in Webresolve 0.1.0 and earlier allows remote attackers to execute arbitrary code by connecting to the server from an IP address that resolves to a long hostname.
CVE-2002-2206 1 Symantec 1 Norton Antivirus 2008-09-05 7.8 HIGH N/A
The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries.
CVE-2002-2207 1 Eric Rescorla 1 Ssldump 2008-09-05 10.0 HIGH N/A
Buffer overflow in ssldump 0.9b2 and earlier, when running in decryption mode, allows remote attackers to execute arbitrary code via a long RSA PreMasterSecret.
CVE-2002-2209 1 Pablo Software Solutions 1 Baby Ftp Server 2008-09-05 10.0 HIGH N/A
Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors.
CVE-2002-2210 1 Openoffice 1 Openoffice 2008-09-05 6.2 MEDIUM N/A
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file.
CVE-2002-2212 2 Fujitsu, Isc 2 Uxp V, Bind 2008-09-05 5.0 MEDIUM N/A
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
CVE-2002-2213 2 Infoblox, Isc 2 Dns One, Bind 2008-09-05 5.0 MEDIUM N/A
The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
CVE-2002-2214 1 Php 1 Php 2008-09-05 5.0 MEDIUM N/A
The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header.
CVE-2002-2215 1 Php 1 Php 2008-09-05 5.0 MEDIUM N/A
The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which triggers an error in the rfc822_write_address function.
CVE-2002-2216 1 Soft3304 1 04webserver 2008-09-05 5.0 MEDIUM N/A
Soft3304 04WebServer before 1.20 does not properly process URL strings, which allows remote attackers to obtain unspecified sensitive information.
CVE-2002-2264 1 Hp 1 Secure Web Server For Tru64 2008-09-05 10.0 HIGH N/A
Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might be the same issue as CVE-2002-2185, but there are insufficient details to be certain.
CVE-2002-2081 1 Microsoft 2 Site Server, Site Server Commerce 2008-09-05 5.0 MEDIUM N/A
cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp.
CVE-2002-2080 1 Floosietek 1 Ftgatepro 2008-09-05 5.0 MEDIUM N/A
Floositek FTGate PRO 1.05 allows remote attackers to cause a denial of service (memory and CPU consumption) via a large number of RCPT TO: messages during an SMTP session.
CVE-2002-1982 1 Icecast 1 Icecast 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.
CVE-2002-2004 1 Compaq 1 Tru64 2008-09-05 5.0 MEDIUM N/A
portmapper in Compaq Tru64 4.0G and 5.0A allows remote attackers to cause a denial of service via a flood of packets.
CVE-2002-2079 2 Mosix Project, Openmosix Project 2 Mosix, Openmosix 2008-09-05 5.0 MEDIUM N/A
mosix-protocol-stack in Multicomputer Operating System for UnIX (MOSIX) 1.5.7 allows remote attackers to cause a denial of service via malformed packets.
CVE-2002-2351 1 Qualcomm 1 Eudora 2008-09-05 6.4 MEDIUM N/A
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).
CVE-2002-2047 1 Sketch 1 Sketch 2008-09-05 10.0 HIGH N/A
The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postscript (EPS) file.
CVE-2002-2007 1 Apache 1 Tomcat 2008-09-05 5.0 MEDIUM N/A
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
CVE-2002-2046 1 Xqus 1 X-news 2008-09-05 7.5 HIGH N/A
x_news.php in X-News (x_news) 1.1 and earlier allows remote attackers to gain administrative privileges by stealing and replaying the md5_password cookie.
CVE-2002-2044 1 Xqus 1 X-stat 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the phpinfo action.
CVE-2002-2043 1 Cyrus 1 Sasl 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in the LDAP and MySQL authentication patch for Cyrus SASL 1.5.24 and 1.5.27 allows remote attackers to execute arbitrary SQL commands and log in as arbitrary POP mail users via the password.
CVE-2002-2010 1 Htdig 1 Htdig 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.
CVE-2002-2018 1 Sas 2 Base, Integration Technologies 2008-09-05 7.2 HIGH N/A
sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.
CVE-2002-2017 1 Sas 2 Base, Integration Technologies 2008-09-05 10.0 HIGH N/A
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.
CVE-2002-2016 1 User-mode Linux 1 User-mode Linux 2008-09-05 7.2 HIGH N/A
User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code.
CVE-2002-2143 1 Mysimplenews 1 Mysimplenews 2008-09-05 7.5 HIGH N/A
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.
CVE-2002-2144 1 Free Peers 1 Bearshare 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in BearShare 4.0.5 and 4.0.6 allows remote attackers to read files outside of the web root by hex-encoding the "/" (forward slash) or "." (dot) characters.