Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1686 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Buffer overflow in lscfg of unknown versions of AIX has unknown impact.
CVE-2002-1941 1 Radiobird Software 1 Web Server 4 Everyone 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in RadioBird WebServer 4 Everyone 1.28 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request with the Host header set.
CVE-2002-1942 1 Imatix 1 Xitami 2008-09-05 5.0 MEDIUM N/A
Imatix Xitami 2.5 b5 does not properly terminate certain Keep-Alive connections that have been broken or closed early, which allows remote attackers to cause a denial of service (crash) via a large number of concurrent sessions.
CVE-2002-1943 1 Safetp 1 Safetp Server 2008-09-05 5.0 MEDIUM N/A
SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a response to a passive mode (PASV) file transfer request.
CVE-2002-1944 1 Motorola 1 Surfboard 2008-09-05 5.0 MEDIUM N/A
Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.
CVE-2002-1945 1 Virtualzone 1 Smartmail Server 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SMTP) or (2) TCP port 110 (POP3).
CVE-2002-1946 1 Videsh Sanchar Nigam Limited 1 Integrated Dialer Software 2008-09-05 2.1 LOW N/A
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows local users to obtain and decrypt the password.
CVE-2002-1959 1 Nagios 1 Nagios 2008-09-05 10.0 HIGH N/A
Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.
CVE-2002-1960 1 Cybozu 1 Share360 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Cybozu Share360 1.1 allows remote attackers to inject arbitrary web script or HTML via an HTML link.
CVE-2002-1961 1 Finjan Software 1 Surfingate 2008-09-05 7.5 HIGH N/A
Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL whose hostname portion uses a fully qualified domain name (FQDN) that ends in a "." (dot).
CVE-2002-1962 1 Finjan Software 1 Surfingate 2008-09-05 7.5 HIGH N/A
Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL with an IP address instead of a hostname.
CVE-2002-1621 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Buffer overflow in the file_comp function in rcp for IBM AIX 4.3.x and 5.1 allows remote attackers to execute arbitrary code.
CVE-2002-1968 1 Com21 1 Doxport 1100 2008-09-05 2.1 LOW N/A
Com21 DOXport 1100 series cable modem running firmware 2.1.1.106, and possibly other versions before 2.1.1.108.003, downloads a DOCSIS configuration file from a TFTP server running on the internal network, which allows local users to modify configuration of the modem via a malicious TFTP server.
CVE-2002-1969 1 The Magic Notebook 1 The Magic Notebook 2008-09-05 5.0 MEDIUM N/A
Magic Notebook 1.0b and 1.1b allows remote attackers to cause a denial of service (crash) via an invalid username during login.
CVE-2002-1970 1 Snortcenter 1 Snortcenter 2008-09-05 2.1 LOW N/A
SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.
CVE-2002-1971 1 Sourcecraft 1 Networking Utils 2008-09-05 10.0 HIGH N/A
The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.
CVE-2002-1956 1 Rox 1 Filer 2008-09-05 2.1 LOW N/A
ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files.
CVE-2002-1800 1 Phprank 1 Phprank 2008-09-05 5.0 MEDIUM N/A
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote attackers to retrieve the administrative password.
CVE-2002-1801 1 Bizdesign 1 Imagefolio 2008-09-05 5.0 MEDIUM N/A
ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.
CVE-2002-1802 1 Xoops 1 Xoops 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag when submitting news.
CVE-2002-1803 1 Francisco Burzi 1 Php-nuke 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
CVE-2002-1804 1 Npds 1 Npds 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
CVE-2002-1831 1 Microsoft 1 Msn Messenger 2008-09-05 5.0 MEDIUM N/A
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
CVE-2002-1832 1 Scaramanga 1 Firestorm Ids 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in the "ipopts decode" functionality in Firestorm IDS 0.4.0 through 0.4.2 allows remote attackers to cause a denial of service (crash) via certain IP options.
CVE-2002-1833 1 Xerox 2 Docutech 6110, Docutech 6115 2008-09-05 7.5 HIGH N/A
The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.
CVE-2002-1799 1 Phprank 1 Phprank 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email parameter to add.php or (2) banurl parameter.
CVE-2002-1839 1 Trend Micro 1 Interscan Viruswall For Windows Nt 2008-09-05 5.0 MEDIUM N/A
Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.
CVE-2002-1840 1 Irssi 1 Irssi 2008-09-05 10.0 HIGH N/A
irssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to access the system.
CVE-2002-1842 1 Perlbot 1 Perlbot 2008-09-05 7.5 HIGH N/A
Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address.
CVE-2002-1798 1 Coxco Support 1 Midicart Php 2008-09-05 6.4 MEDIUM N/A
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.
CVE-2002-1854 1 Rlaj 1 Rlaj Whois 2008-09-05 10.0 HIGH N/A
Rlaj whois CGI script (whois.cgi) 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain name field.
CVE-2002-1855 1 Macromedia 1 Jrun 2008-09-05 5.0 MEDIUM N/A
Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVE-2002-1856 1 Hp 1 Application Server 2008-09-05 5.0 MEDIUM N/A
HP Application Server 8.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVE-2002-1857 1 Jo 1 Jo Webserver 2008-09-05 5.0 MEDIUM N/A
jo! jo Webserver 1.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVE-2002-1858 1 Oracle 1 Application Server 2008-09-05 5.0 MEDIUM N/A
Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
CVE-2002-1935 1 Pingtel 1 Xpressa 2008-09-05 5.0 MEDIUM N/A
Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar.
CVE-2002-1805 1 Dacode 1 Dacode 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
CVE-2002-1934 1 Pingtel 1 Xpressa 2008-09-05 5.0 MEDIUM N/A
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of the Admin password, MD5 hash of the physical password, and other registration information.
CVE-2002-1428 1 Dotproject 1 Dotproject 2008-09-05 10.0 HIGH N/A
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.
CVE-2002-1481 1 Phpgb 1 Phpgb 2008-09-05 7.5 HIGH N/A
savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.
CVE-2002-1480 1 Phpgb 1 Phpgb 2008-09-05 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.
CVE-2002-1478 1 The Cacti Group 1 Cacti 2008-09-05 10.0 HIGH N/A
Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.
CVE-2002-1442 1 Google 1 Toolbar 2008-09-05 7.5 HIGH N/A
The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window's location to the toolbar's configuration URL, which bypasses the origin verification check.
CVE-2002-1433 1 Kerio 1 Kerio Mailserver 2008-09-05 5.0 MEDIUM N/A
Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.
CVE-2002-1431 1 Belkin 1 F5d5230-4 4-port Cable Dsl Gateway Router 2008-09-05 7.5 HIGH N/A
Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host to an internal web server, which allows remote attackers to hide which host is being used to access the web server.
CVE-2002-1430 1 Synthetic Reality 1 Sympoll 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters.
CVE-2002-1227 1 Pam 1 Pam 2008-09-05 7.5 HIGH N/A
PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.
CVE-2002-1441 1 Tomahawk Technologies 1 Steelarrow 2008-09-05 7.5 HIGH N/A
Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding request.
CVE-2002-1429 1 Endity.com 1 Shoutbox 2008-09-05 5.0 MEDIUM N/A
Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter.
CVE-2002-1210 1 Qualcomm 1 Eudora 2008-09-05 5.0 MEDIUM N/A
Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context.