Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1883 1 Trolltech 1 Qt Assistant 2008-09-05 6.4 MEDIUM N/A
Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTML pages and cause a denial of service.
CVE-2002-1884 1 Py-membres 1 Py-membres 2008-09-05 7.5 HIGH N/A
index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin".
CVE-2002-1885 1 Powerphlogger 1 Powerphlogger 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter.
CVE-2002-1886 1 Tightauction 1 Tightauction 2008-09-05 5.0 MEDIUM N/A
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password.
CVE-2002-1887 1 Gregory Kokanosky 1 Phpmynewsletter 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.
CVE-2002-1888 1 Commonname 1 Commonname Toolbar 2008-09-05 2.1 LOW N/A
CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names.
CVE-2002-1909 1 Click2learn 1 Ingenium Learning Management System 2008-09-05 5.0 MEDIUM N/A
Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password.
CVE-2002-1910 1 Click2learn 1 Ingenium Learning Management System 2008-09-05 5.0 MEDIUM N/A
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.
CVE-2002-1874 1 Astrocam 1 Astrocam 2008-09-05 10.0 HIGH N/A
astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.
CVE-2002-1911 1 Zonelabs 1 Zonealarm 2008-09-05 5.0 MEDIUM N/A
ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.
CVE-2002-1913 1 Myphpnuke 1 Myphpnuke 2008-09-05 5.0 MEDIUM N/A
phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable.
CVE-2002-1914 1 Dump 1 Dump 2008-09-05 2.1 LOW N/A
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.
CVE-2002-1915 3 Freebsd, Netbsd, Openbsd 3 Freebsd, Netbsd, Openbsd 2008-09-05 2.1 LOW N/A
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
CVE-2002-1916 1 Pirch 2 Pirch Irc, Ruspirch 2008-09-05 5.0 MEDIUM N/A
Pirch and RusPirch, when auto-log is enabled, allows remote attackers to cause a denial of service (crash) via a nickname containing an MS-DOS device name such as AUX, which is inserted into a filename for saving queries.
CVE-2002-1929 1 Php Arena 1 Pafiledb 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary web script or HTML via the query string in the (1) rate, (2) email, or (3) download actions.
CVE-2002-1930 1 An 1 An-httpd 2008-09-05 7.5 HIGH N/A
Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.
CVE-2002-1931 1 Php Arena 1 Pafiledb 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string.
CVE-2002-1933 1 Microsoft 1 Windows 2000 Terminal Services 2008-09-05 7.2 HIGH N/A
The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
CVE-2002-1947 1 Webmin 1 Webmin 2008-09-05 6.4 MEDIUM N/A
Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session.
CVE-2002-1948 1 Gringotts 1 Gringotts 2008-09-05 7.2 HIGH N/A
Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors.
CVE-2002-1949 1 Iomega 1 Nas 2008-09-05 5.0 MEDIUM N/A
The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password.
CVE-2002-1950 1 Phprank 1 Phprank 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.
CVE-2002-1959 1 Nagios 1 Nagios 2008-09-05 10.0 HIGH N/A
Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.
CVE-2002-1960 1 Cybozu 1 Share360 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Cybozu Share360 1.1 allows remote attackers to inject arbitrary web script or HTML via an HTML link.
CVE-2002-1961 1 Finjan Software 1 Surfingate 2008-09-05 7.5 HIGH N/A
Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL whose hostname portion uses a fully qualified domain name (FQDN) that ends in a "." (dot).
CVE-2002-1962 1 Finjan Software 1 Surfingate 2008-09-05 7.5 HIGH N/A
Finjan Software SurfinGate 6.0 and 6.0 1 allows remote attackers to bypass URL access restrictions via a URL with an IP address instead of a hostname.
CVE-2002-1810 1 D-link 1 Dwl-900ap\+ 2008-09-05 7.5 HIGH N/A
D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and read the config.img file, which contains sensitive information such as the administrative password, the WEP encryption keys, and network configuration information.
CVE-2002-1784 1 Hp 1 Tru64 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in inetd in HP Tru64 Unix 4.0f through 5.1a allows remote attackers to cause a denial of service via unknown attack vectors.
CVE-2002-1968 1 Com21 1 Doxport 1100 2008-09-05 2.1 LOW N/A
Com21 DOXport 1100 series cable modem running firmware 2.1.1.106, and possibly other versions before 2.1.1.108.003, downloads a DOCSIS configuration file from a TFTP server running on the internal network, which allows local users to modify configuration of the modem via a malicious TFTP server.
CVE-2002-1969 1 The Magic Notebook 1 The Magic Notebook 2008-09-05 5.0 MEDIUM N/A
Magic Notebook 1.0b and 1.1b allows remote attackers to cause a denial of service (crash) via an invalid username during login.
CVE-2002-1970 1 Snortcenter 1 Snortcenter 2008-09-05 2.1 LOW N/A
SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.
CVE-2002-1971 1 Sourcecraft 1 Networking Utils 2008-09-05 10.0 HIGH N/A
The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.
CVE-2002-1785 1 Zeus Technologies 1 Zeus Web Server 2008-09-05 1.9 LOW N/A
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi.
CVE-2002-1807 1 Phpwebsite 1 Phpwebsite 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
CVE-2002-1934 1 Pingtel 1 Xpressa 2008-09-05 5.0 MEDIUM N/A
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allows attackers to obtain the MD5 hash of the Admin password, MD5 hash of the physical password, and other registration information.
CVE-2002-1928 1 Software602 1 602pro Lan Suite 2008-09-05 5.0 MEDIUM N/A
602Pro LAN SUITE 2002 allows remote attackers to view the directory tree via an HTTP GET request with a trailing "~" (tilde) or ".bak" extension.
CVE-2002-1935 1 Pingtel 1 Xpressa 2008-09-05 5.0 MEDIUM N/A
Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a Session Identification Protocol (SIP) request, which allows remote attackers to avoid registering with the SIP registrar.
CVE-2002-1806 1 Drupal 1 Drupal 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
CVE-2002-1438 1 Novell 1 Netware 2008-09-05 5.0 MEDIUM N/A
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.
CVE-2002-1573 1 Linux 1 Linux Kernel 2008-09-05 10.0 HIGH N/A
Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling."
CVE-2002-1572 1 Linux 1 Linux Kernel 2008-09-05 10.0 HIGH N/A
Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.
CVE-2002-1571 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.
CVE-2002-1559 1 Research Systems Inc. 1 Ion Script 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.
CVE-2002-1533 1 Jetty 1 Jetty 2008-09-05 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).
CVE-2002-1532 1 Surfcontrol 1 Superscout Email Filter 2008-09-05 5.0 MEDIUM N/A
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it.
CVE-2002-1531 1 Surfcontrol 1 Superscout Email Filter 2008-09-05 5.0 MEDIUM N/A
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter.
CVE-2002-1530 1 Surfcontrol 1 Superscout Email Filter 2008-09-05 5.0 MEDIUM N/A
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.
CVE-2002-1529 1 Surfcontrol 1 Superscout Email Filter 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter.
CVE-2002-1528 1 Mondosoft 1 Mondosearch 2008-09-05 5.0 MEDIUM N/A
MsmMask.exe in MondoSearch 4.4 allows remote attackers to obtain the source code of scripts via the mask parameter.
CVE-2002-1527 1 Emumail 1 Emu Webmail 2008-09-05 5.0 MEDIUM N/A
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message.