Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1591 1 Aol 1 Instant Messenger 2008-09-05 7.5 HIGH N/A
AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass intended access restrictions.
CVE-2002-1788 1 Kim Storm 1 Nn 2008-09-05 7.5 HIGH N/A
Format string vulnerability in the nn_exitmsg function in nn 6.6.0 through 6.6.3 allows remote NNTP servers to execute arbitrary code via format strings in server responses.
CVE-2002-1860 1 Pramati 1 Pramati Server 2008-09-05 5.0 MEDIUM N/A
Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVE-2002-1965 1 Imatix 1 Xitami 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web script or HTML via the (1) Javascript events, as demonstrated via an onerror event in an IMG SRC tag or (2) User-Agent field in an HTTP GET request.
CVE-2002-1928 1 Software602 1 602pro Lan Suite 2008-09-05 5.0 MEDIUM N/A
602Pro LAN SUITE 2002 allows remote attackers to view the directory tree via an HTTP GET request with a trailing "~" (tilde) or ".bak" extension.
CVE-2002-1960 1 Cybozu 1 Share360 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Cybozu Share360 1.1 allows remote attackers to inject arbitrary web script or HTML via an HTML link.
CVE-2002-1826 1 Grsecurity 1 Grsecurity Kernel Patch 2008-09-05 4.6 MEDIUM N/A
grsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or /dev/kmem to kernel memory.
CVE-2002-1805 1 Dacode 1 Dacode 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
CVE-2002-1941 1 Radiobird Software 1 Web Server 4 Everyone 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in RadioBird WebServer 4 Everyone 1.28 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request with the Host header set.
CVE-2002-1964 1 Wesmo 1 Phpeventcalendar 2008-09-05 7.5 HIGH N/A
Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors.
CVE-2002-1958 1 Kmmail 1 Kmmail 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via (1) javascript in onmouseover or other attributes in "safe" HTML tags such as the "b" tag, or (2) the Subject field.
CVE-2002-1940 1 Jacob Navia 1 Lcc-win32 2008-09-05 5.0 MEDIUM N/A
LCC-Win32 3.2 compiler, when running on Windows 95, 98, or ME, writes portions of previously used memory after the import table, which could allow attackers to gain sensitive information. NOTE: it has been reported that this problem is due to the OS and not the application.
CVE-2002-1939 1 Flashfxp 1 Flashfxp 2008-09-05 2.1 LOW N/A
FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties.
CVE-2002-1938 1 Virgil 1 Cgi Scanner 2008-09-05 7.5 HIGH N/A
Virgil CGI Scanner 0.9 allows remote attackers to execute arbitrary commands via the (1) tar (TARGET) or (2) zielport (ZIELPORT) parameters.
CVE-2002-1828 1 Savant 1 Savant Webserver 2008-09-05 5.0 MEDIUM N/A
Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value.
CVE-2002-1937 1 Symantec 3 Firewall Vpn Appliance 100, Firewall Vpn Appliance 200, Firewall Vpn Appliance 200r 2008-09-05 5.0 MEDIUM N/A
Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password.
CVE-2002-1936 1 Utstarcom 1 Bas 1000 2008-09-05 7.5 HIGH N/A
UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field", (2) guru account with a password of "*3noguru", (3) snmp account with a password of "snmp", or (4) dbase account with a password of "dbase".
CVE-2002-1957 1 Pen 1 Pen 2008-09-05 7.5 HIGH N/A
Buffer overflow in the netlog function in pen.c for Pen 0.9.1 and 0.9.2 allows remote attackers to execute arbitrary commands via malformed log messages.
CVE-2002-1961 1 Finjan Software 1 Surfingate 2008-09-05 7.5 HIGH N/A
Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL whose hostname portion uses a fully qualified domain name (FQDN) that ends in a "." (dot).
CVE-2002-1920 1 Datawizard 1 Ftpxq 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name.
CVE-2002-1971 1 Sourcecraft 1 Networking Utils 2008-09-05 10.0 HIGH N/A
The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.
CVE-2002-1962 1 Finjan Software 1 Surfingate 2008-09-05 7.5 HIGH N/A
Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL with an IP address instead of a hostname.
CVE-2002-1942 1 Imatix 1 Xitami 2008-09-05 5.0 MEDIUM N/A
Imatix Xitami 2.5 b5 does not properly terminate certain Keep-Alive connections that have been broken or closed early, which allows remote attackers to cause a denial of service (crash) via a large number of concurrent sessions.
CVE-2002-1690 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
CVE-2002-1689 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
CVE-2002-1917 1 Geeklog 1 Geeklog 2008-09-05 5.0 MEDIUM N/A
CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.
CVE-2002-1907 1 Telcondex 1 Simplewebserver 2008-09-05 5.0 MEDIUM N/A
TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
CVE-2002-1906 1 Polycom 1 Viavideo 2008-09-05 5.0 MEDIUM N/A
The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending incomplete HTTP requests and leaving the connections open.
CVE-2002-1905 1 Polycom 1 Viavideo 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
CVE-2002-1904 1 Gaztek 1 Ghttpd 2008-09-05 7.5 HIGH N/A
Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET request.
CVE-2002-1943 1 Safetp 1 Safetp Server 2008-09-05 5.0 MEDIUM N/A
SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a response to a passive mode (PASV) file transfer request.
CVE-2002-1903 1 University Of Washington 1 Pine 2008-09-05 5.0 MEDIUM N/A
Pine 4.2.1 through 4.4.4 puts Unix usernames and/or uid into Sender: and X-Sender: headers, which could allow remote attackers to obtain sensitive information.
CVE-2002-1902 1 Markus Triska 1 Cgiforum 2008-09-05 5.0 MEDIUM N/A
CGIForum 1.0 through 1.05 allows remote attackers to cause a denial of service (infinite recursion) by creating a message board post that is a child of an outdated parent.
CVE-2002-1821 1 Ultimate Php Board 1 Ultimate Php Board 2008-09-05 4.6 MEDIUM N/A
Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php.
CVE-2002-1901 1 Bodo Bauer 1 Bbgallery 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Bodo Bauer BBGallery 1.0 allows remote attackers to inject arbitrary web script or HTML via image tags.
CVE-2002-1900 1 Pinboard 1 Pinboard 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists.
CVE-2002-1888 1 Commonname 1 Commonname Toolbar 2008-09-05 2.1 LOW N/A
CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.
CVE-2002-1820 1 Ultimate Php Board 1 Ultimate Php Board 2008-09-05 7.5 HIGH N/A
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a."
CVE-2002-1819 1 Tinyhttpd 1 Tinyhttpd 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in TinyHTTPD 0.1 .0 allows remote attackers to read or execute arbitrary files via a ".." (dot dot) in the URL.
CVE-2002-1887 1 Gregory Kokanosky 1 Phpmynewsletter 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.
CVE-2002-1886 1 Tightauction 1 Tightauction 2008-09-05 5.0 MEDIUM N/A
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.
CVE-2002-1818 1 Ez Systems 1 Httpbench 2008-09-05 5.0 MEDIUM N/A
ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSite parameter.
CVE-2002-1817 1 Symantec Veritas 1 Cluster Server 2008-09-05 7.5 HIGH N/A
Unknown vulnerability in Veritas Cluster Server (VCS) 1.2 for WindowsNT, Cluster Server 1.3.0 for Solaris, and Cluster Server 1.3.1 for HP-UX allows attackers to gain privileges via unknown attack vectors.
CVE-2002-1885 1 Powerphlogger 1 Powerphlogger 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.
CVE-2002-1816 1 Yann Ramin 1 Atphttpd 2008-09-05 7.5 HIGH N/A
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
CVE-2002-1878 1 W-agora 1 W-agora 2008-09-05 5.0 MEDIUM N/A
PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.
CVE-2002-1815 1 Aquonics Scripting 1 Aquonics File Manager 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in source.php and source.cgi in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
CVE-2002-1814 4 Gnome, Mandrakesoft, Redhat and 1 more 4 Bonobo, Mandrake Linux, Linux and 1 more 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.
CVE-2002-1875 1 Mcafee 1 Entercept Agent 2008-09-05 4.6 MEDIUM N/A
Entercept Agent 2.5 agent for Windows, released before May 21, 2002, allows local administrative users to obtain the entercept agent password, which could allow the administrators to log on as the entercept_agent account and conceal their identity.
CVE-2002-1813 1 Aol 1 Instant Messenger 2008-09-05 2.6 LOW N/A
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link.