Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2089 1 Sun 1 Solaris 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in rcp in Solaris 9.0 allows local users to execute arbitrary code via a long command line argument.
CVE-2002-2090 1 Caucho Technology 1 Resin 2008-09-05 5.0 MEDIUM N/A
Caucho Technology Resin server 2.1.1 to 2.1.2 allows remote attackers to obtain server's root path via requests for MS-DOS device names such as lpt9.xtp.
CVE-2002-2096 1 Novell 1 Netware 2008-09-05 7.5 HIGH N/A
Buffer overflow in Novell Remote Manager module, httpstk.nlm, in NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary code via a long (1) username or (2) password.
CVE-2002-2100 1 Microsoft 1 Outlook 2008-09-05 5.0 MEDIUM N/A
Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
CVE-2002-2101 1 Microsoft 1 Outlook 2008-09-05 7.5 HIGH N/A
Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
CVE-2002-2102 1 Jcraft 1 Jzlib 2008-09-05 5.0 MEDIUM N/A
InfBlocks.java in JCraft JZlib before 0.0.7 allow remote attackers to cause a denial of service (NullPointerException) via an invalid block of deflated data.
CVE-2002-2103 1 Apache 1 Http Server 2008-09-05 5.0 MEDIUM N/A
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
CVE-2002-2107 1 Veridis 1 Openkeyserver 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the lookup script in Veridis OpenKeyServer (OKS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CVE-2002-2108 1 Sony 1 Vaio Manual Cybersupport 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in the "VAIO Manual" software in certain Sony VAIO personal computers sold from November 2001 to January 2002, allows remote attackers to modify data via a web page or HTML e-mail.
CVE-2002-2109 1 Matt Wright 1 Formmail 2008-09-05 7.5 HIGH N/A
Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname) portion of the referer.
CVE-2002-2110 1 Rca 1 Digital Cable Modem 2008-09-05 5.0 MEDIUM N/A
The RCA Digital Cable Modems DCM225 and DCM225E allow remote attackers to cause a denial of service (modem device reset) by connecting to port 80 on the 10.0.0.0/8 device.
CVE-2002-2116 1 Netgear 2 Rm356, Rt338 2008-09-05 5.0 MEDIUM N/A
Netgear RM-356 and RT-338 series SOHO routers allow remote attackers to cause a denial of service (crash) via a UDP port scan, as demonstrated using nmap.
CVE-2002-2117 1 Microsoft 1 Windows Xp 2008-09-05 5.0 MEDIUM N/A
Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP).
CVE-2002-2119 1 Novell 1 Edirectory 2008-09-05 7.5 HIGH N/A
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.
CVE-2002-2120 1 Qnx 1 Rtos 2008-09-05 4.6 MEDIUM N/A
Multiple buffer overflows in QNX RTOS 4.25 may allow attackers to execute arbitrary code via long filename arguments to (1) Watcom or (2) int10.
CVE-2002-2122 1 Pointsec Mobile Technologies 1 Pointsec 2008-09-05 2.1 LOW N/A
Pointsec before 1.2 for PalmOS stores a user's PIN number in memory in plaintext, which allows a local attacker who steals an unlocked Palm to retrieve the PIN by dumping memory.
CVE-2002-2145 1 Savant 1 Savant Webserver 2008-09-05 7.5 HIGH N/A
Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a '.' (%2e) at the end of the filename.
CVE-2002-2126 1 Pedestal Software 1 Integrity Protection Driver 2008-09-05 2.1 LOW N/A
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.
CVE-2002-2128 1 W-agora 1 W-agora 2008-09-05 4.6 MEDIUM N/A
editform.php in w-Agora 4.1.5 allows local users to execute arbitrary PHP code via .. (dot dot) sequences in the file parameter.
CVE-2002-2146 1 Savant 1 Savant Webserver 2008-09-05 7.5 HIGH N/A
cgitest.exe in Savant Web Server 3.1 and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request.
CVE-2002-2155 1 Cerulean Studios 1 Trillian 2008-09-05 7.5 HIGH N/A
Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string specifiers in the name.
CVE-2002-2156 1 Cerulean Studios 1 Trillian 2008-09-05 7.5 HIGH N/A
Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response.
CVE-2002-2158 1 Zendocs 1 Zentrack 2008-09-05 5.0 MEDIUM N/A
zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message.
CVE-2002-2161 1 Kerio 1 Personal Firewall 2008-09-05 5.0 MEDIUM N/A
Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to cause a denial of service (hang and CPU consumption) via a SYN packet flood.
CVE-2002-2162 1 Cerulean Studios 1 Trillian 2008-09-05 4.6 MEDIUM N/A
Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts.
CVE-2002-2163 1 Killervault 1 Kvpoll 2008-09-05 4.0 MEDIUM N/A
KvPoll 1.1 allows remote authenticated users to vote more than once by setting the "already_voted" cookie by various methods, including a direct call to clear_cookies.php.
CVE-2002-2164 1 Microsoft 1 Outlook Express 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.
CVE-2002-2165 1 Imho 1 Imho Webmail 2008-09-05 2.1 LOW N/A
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.
CVE-2002-2168 1 Thorsten Korner 1 123tkshop 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php.
CVE-2002-2169 1 Aol 1 Instant Messenger 2008-09-05 5.0 MEDIUM N/A
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.
CVE-2002-2170 1 Working Resources Inc. 1 Badblue 2008-09-05 7.5 HIGH N/A
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.
CVE-2002-2172 1 Shana 2 Informed Designer, Informed Filler 2008-09-05 2.1 LOW N/A
Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information.
CVE-2002-2173 1 Cerulean Studios 1 Trillian 2008-09-05 7.5 HIGH N/A
Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a long DCC Chat message.
CVE-2002-2174 1 Software602 1 602pro Lan Suite 2008-09-05 5.0 MEDIUM N/A
The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) via a large number of connections.
CVE-2002-2176 1 Phpbb Group 1 Phpbb 2008-09-05 10.0 HIGH N/A
SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.
CVE-2002-2183 1 Phpshare 1 Phpshare 2008-09-05 7.5 HIGH N/A
phpShare.php in phpShare before 0.6 beta 3 allows remote attackers to include and execute arbitrary PHP scripts from remote servers.
CVE-2002-2184 1 Digi-net Technologies 1 Digichat 2008-09-05 5.0 MEDIUM N/A
Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet.
CVE-2002-2186 1 Macromedia 1 Jrun 2008-09-05 5.0 MEDIUM N/A
Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL.
CVE-2002-2187 1 Macromedia 1 Jrun 2008-09-05 5.0 MEDIUM N/A
Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.
CVE-2002-2188 1 Openbsd 1 Openbsd 2008-09-05 4.9 MEDIUM N/A
OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error.
CVE-2002-2189 2 Activxperts Software, Microsoft 2 Activwebserver, Windows 2003 Server 2008-09-05 5.1 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.
CVE-2002-2190 1 Artscore Studios 1 Cutecast Forum 2008-09-05 7.5 HIGH N/A
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
CVE-2002-2192 1 Perception 1 Liteserve 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders.
CVE-2002-2193 1 Mojo Mail 1 Mojo Mail 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter.
CVE-2002-2195 1 Nullsoft 1 Winamp 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.
CVE-2002-2196 1 Samba 1 Samba 2008-09-05 7.5 HIGH N/A
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
CVE-2002-2198 1 Zmailer 1 Zmailer 2008-09-05 10.0 HIGH N/A
Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing from an IPv6 address, possibly using an address that resolves to a long hostname.
CVE-2002-2218 1 Sips 1 Sips 2008-09-05 10.0 HIGH N/A
CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impact, possibly gaining privileges or modifying critical configuration, via a CRLF sequence in a key value.
CVE-2002-2220 1 Chetcpasswd 1 Chetcpasswd 2008-09-05 6.2 MEDIUM N/A
Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors.
CVE-2002-2221 1 Chetcpasswd 1 Chetcpasswd 2008-09-05 6.2 MEDIUM N/A
Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639.