Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1924 1 Apc 1 Powerchute 2008-09-05 5.0 MEDIUM N/A
PowerChute plus 5.0.2 creates a "Pwrchute" directory during installation that is shared and world writeable, which could allow remote attackers to modify or create files in that directory.
CVE-2002-1922 1 Jelsoft 1 Vbulletin 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables.
CVE-2002-1957 1 Pen 1 Pen 2008-09-05 7.5 HIGH N/A
Buffer overflow in the netlog function in pen.c for Pen 0.9.1 and 0.9.2 allows remote attackers to execute arbitrary commands via malformed log messages.
CVE-2002-1920 1 Datawizard 1 Ftpxq 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name.
CVE-2002-1917 1 Geeklog 1 Geeklog 2008-09-05 5.0 MEDIUM N/A
CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attackers to obtain e-mail addresses by injecting a CRLF into the Subject field and adding a BCC mail header.
CVE-2002-1888 1 Commonname 1 Commonname Toolbar 2008-09-05 2.1 LOW N/A
CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.
CVE-2002-1887 1 Gregory Kokanosky 1 Phpmynewsletter 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.
CVE-2002-1886 1 Tightauction 1 Tightauction 2008-09-05 5.0 MEDIUM N/A
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.
CVE-2002-1885 1 Powerphlogger 1 Powerphlogger 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.
CVE-2002-1884 1 Py-membres 1 Py-membres 2008-09-05 7.5 HIGH N/A
index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin".
CVE-2002-1883 1 Trolltech 1 Qt Assistant 2008-09-05 6.4 MEDIUM N/A
Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTML pages and cause a denial of service.
CVE-2002-1882 1 Oracle 1 E-business Suite 2008-09-05 7.5 HIGH N/A
Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.
CVE-2002-1881 1 Macromedia 1 Flash Player 2008-09-05 5.0 MEDIUM N/A
Macromedia Flash Player 4.0 r12 through 6.0.47.0 allows remote attackers to cause a denial of service (web browser crash) via malformed content in a Flash Shockwave (.SWF) file, as demonstrated by by ROT13 encoding the body of the file but not the headers.
CVE-2002-1880 1 Lokwa 1 Lokwabb 2008-09-05 5.0 MEDIUM N/A
LokwaBB 1.2.2 allows remote attackers to read arbitrary messages by modifying the pmid parameter to pm.php.
CVE-2002-1879 1 Lokwa 1 Lokwabb 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php.
CVE-2002-1878 1 W-agora 1 W-agora 2008-09-05 5.0 MEDIUM N/A
PHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.
CVE-2002-1875 1 Mcafee 1 Entercept Agent 2008-09-05 4.6 MEDIUM N/A
Entercept Agent 2.5 agent for Windows, released before May 21, 2002, allows local administrative users to obtain the entercept agent password, which could allow the administrators to log on as the entercept_agent account and conceal their identity.
CVE-2002-1872 1 Microsoft 1 Sql Server 2008-09-05 5.0 MEDIUM N/A
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
CVE-2002-1870 1 Sws 1 Sws Simple Web Server 2008-09-05 7.5 HIGH N/A
Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution.
CVE-2002-1838 1 Steve Sachs 1 Charities.cron 2008-09-05 5.0 MEDIUM N/A
Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.
CVE-2002-1837 1 Ids 1 Ids 2008-09-05 5.0 MEDIUM N/A
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.
CVE-2002-1836 1 Xerox 2 Docutech 6110, Docutech 6115 2008-09-05 5.0 MEDIUM N/A
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive files.
CVE-2002-1835 1 Xerox 2 Docutech 6110, Docutech 6115 2008-09-05 7.5 HIGH N/A
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device.
CVE-2002-1834 1 Xerox 2 Docutech 6110, Docutech 6115 2008-09-05 6.4 MEDIUM N/A
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.
CVE-2002-1833 1 Xerox 2 Docutech 6110, Docutech 6115 2008-09-05 7.5 HIGH N/A
The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.
CVE-2002-1832 1 Scaramanga 1 Firestorm Ids 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.
CVE-2002-1831 1 Microsoft 1 Msn Messenger 2008-09-05 5.0 MEDIUM N/A
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
CVE-2002-1779 1 Symantec 1 Norton Personal Firewall 2008-09-05 7.5 HIGH N/A
The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305).
CVE-2002-1761 1 Phprojekt 1 Phprojekt 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in PHProjekt 2.0 through 3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences.
CVE-2002-1690 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.
CVE-2002-1689 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
CVE-2002-1687 1 Ibm 1 Aix 2008-09-05 2.1 LOW N/A
Buffer overflow in the diagnostics library in AIX allows local users to "cause data and instructions to be overwritten" via a long DIAGNOSTICS environment variable.
CVE-2002-1686 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Buffer overflow in lscfg of unknown versions of AIX has unknown impact.
CVE-2002-1591 1 Aol 1 Instant Messenger 2008-09-05 7.5 HIGH N/A
AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass intended access restrictions.
CVE-2002-1806 1 Drupal 1 Drupal 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
CVE-2002-1935 1 Pingtel 1 Xpressa 2008-09-05 5.0 MEDIUM N/A
Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar.
CVE-2002-1874 1 Astrocam 1 Astrocam 2008-09-05 10.0 HIGH N/A
astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.
CVE-2002-1910 1 Click2learn 1 Ingenium Learning Management System 2008-09-05 5.0 MEDIUM N/A
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.
CVE-2002-1911 1 Zonelabs 1 Zonealarm 2008-09-05 5.0 MEDIUM N/A
ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.
CVE-2002-1913 1 Myphpnuke 1 Myphpnuke 2008-09-05 5.0 MEDIUM N/A
phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable.
CVE-2002-1914 1 Dump 1 Dump 2008-09-05 2.1 LOW N/A
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.
CVE-2002-1915 3 Freebsd, Netbsd, Openbsd 3 Freebsd, Netbsd, Openbsd 2008-09-05 2.1 LOW N/A
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
CVE-2002-1916 1 Pirch 2 Pirch Irc, Ruspirch 2008-09-05 5.0 MEDIUM N/A
Pirch and RusPirch, when auto-log is enabled, allows remote attackers to cause a denial of service (crash) via a nickname containing an MS-DOS device name such as AUX, which is inserted into a filename for saving queries.
CVE-2002-1947 1 Webmin 1 Webmin 2008-09-05 6.4 MEDIUM N/A
Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session.
CVE-2002-1797 1 Hp 1 Chaivm 2008-09-05 4.6 MEDIUM N/A
ChaiVM for HP color LaserJet 4500 and 4550 or HP LaserJet 4100 and 8150 does not properly enforce access control restrictions, which could allow local users to add, delete, or modify any services hosted by the ChaiServer.
CVE-2002-1948 1 Gringotts 1 Gringotts 2008-09-05 7.2 HIGH N/A
Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors.
CVE-2002-1851 1 Ipswitch 1 Ws Ftp Pro 2008-09-05 7.5 HIGH N/A
Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.
CVE-2002-1949 1 Iomega 1 Nas 2008-09-05 5.0 MEDIUM N/A
The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.
CVE-2002-1641 1 Oracle 1 Application Server Web Cache 2008-09-05 10.0 HIGH N/A
Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors.
CVE-2002-1950 1 Phprank 1 Phprank 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.