Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1532 1 Surfcontrol 1 Superscout Email Filter 2008-09-05 5.0 MEDIUM N/A
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it.
CVE-2002-1533 1 Jetty 1 Jetty 2008-09-05 5.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).
CVE-2002-1534 1 Macromedia 1 Flash Player 2008-09-05 5.0 MEDIUM N/A
Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share.
CVE-2002-1535 1 Symantec 2 Enterprise Firewall, Raptor Firewall 2008-09-05 5.0 MEDIUM N/A
Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present.
CVE-2002-1536 1 Hans Persson 1 Molly 2008-09-05 7.5 HIGH N/A
Molly IRC bot 0.5 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $host variable for nslookup.pl, (2) the $to, $from, or $message variables in pop.pl, (3) the $words or $text variables in sms.pl, or (4) the $server or $printer variables in hpled.pl.
CVE-2002-1537 1 Phpbb Group 1 Phpbb 2008-09-05 10.0 HIGH N/A
admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".
CVE-2002-1538 1 Acuma 1 Acusend 2008-09-05 5.0 MEDIUM N/A
Acuma Acusend 4, and possibly earlier versions, allows remote authenticated users to read the reports of other users by inferring the full URL, whose name is easily predictable.
CVE-2002-1539 1 Alt-n 1 Mdaemon 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.
CVE-2002-1559 1 Research Systems Inc. 1 Ion Script 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter.
CVE-2002-1571 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.
CVE-2002-1572 1 Linux 1 Linux Kernel 2008-09-05 10.0 HIGH N/A
Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.
CVE-2002-1573 1 Linux 1 Linux Kernel 2008-09-05 10.0 HIGH N/A
Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling."
CVE-2002-1582 1 Mailreader.com 1 Mailreader.com 2008-09-05 10.0 HIGH N/A
compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi.
CVE-2002-1583 1 Ibm 1 Db2 Universal Database 2008-09-05 7.2 HIGH N/A
Buffer overflow in sqllib/security/db2ckpw for IBM DB2 Universal Database 6.0 and 7.0 allows local users to execute arbitrary code via a long username that is read from a file descriptor argument.
CVE-2002-1223 1 Kde 1 Kde 2008-09-05 7.5 HIGH N/A
Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a denial of service or execute arbitrary code via a modified .ps (PostScript) input file.
CVE-2002-1224 1 Kde 1 Kde 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.
CVE-2002-1251 1 Log2mail 1 Log2mail 2008-09-05 10.0 HIGH N/A
Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message.
CVE-2002-1253 1 Abuse 1 Abuse 2008-09-05 7.2 HIGH N/A
Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.
CVE-2002-1541 1 Working Resources Inc. 1 Badblue 2008-09-05 7.5 HIGH N/A
BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).
CVE-2002-1542 1 Solarwinds 1 Tftp Server 2008-09-05 5.0 MEDIUM N/A
SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.
CVE-2002-1543 1 Netbsd 1 Netbsd 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in trek on NetBSD 1.5 through 1.5.3 allows local users to gain privileges via long keyboard input.
CVE-2002-1544 1 Cooolsoft 1 Personal Ftp Server 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get.
CVE-2002-1545 1 Cooolsoft 1 Personal Ftp Server 2008-09-05 5.0 MEDIUM N/A
CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.
CVE-2002-1551 1 Ibm 1 Aix 2008-09-05 4.6 MEDIUM N/A
Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.
CVE-2002-1546 1 Brs 1 Webweaver 2008-09-05 7.5 HIGH N/A
BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HTTP request containing a "/./" sequence.
CVE-2002-1547 1 Juniper 1 Netscreen Screenos 2008-09-05 5.0 MEDIUM N/A
Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability than CVE-2001-0144.
CVE-2002-1549 1 Light Httpd 1 Light Httpd 2008-09-05 7.5 HIGH N/A
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.
CVE-2002-1550 1 Ibm 1 Aix 2008-09-05 4.6 MEDIUM N/A
dump_smutil.sh in IBM AIX allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2002-1560 1 Martin Bauer 1 Gbook 2008-09-05 10.0 HIGH N/A
index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.
CVE-2002-0851 1 Isdn4linux 1 Isdn4linux 2008-09-05 7.2 HIGH N/A
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog.
CVE-2002-0827 1 Caldera 2 Openunix, Unixware 2008-09-05 7.2 HIGH N/A
Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.
CVE-2002-0825 1 Padl Software 1 Nss Ldap 2008-09-05 7.5 HIGH N/A
Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
CVE-2002-0916 1 Stellar-x Software 1 Msntauth 2008-09-05 7.5 HIGH N/A
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
CVE-2002-0876 1 Evolvable Corporation 1 Shambala Server 2008-09-05 5.0 MEDIUM N/A
Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.
CVE-2002-0877 1 Evolvable Corporation 1 Shambala Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in the FTP server for Shambala 4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) LIST (ls) or (2) GET commands.
CVE-2002-0878 1 Logisense 2 Dns Manager System, Hawk-i 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.
CVE-2002-0879 1 Gafware 1 Cfximage 2008-09-05 5.0 MEDIUM N/A
showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.
CVE-2002-0822 1 Ethereal Group 1 Ethereal 2008-09-05 7.5 HIGH N/A
Ethereal 0.9.4 and earlier allows remote attackers to cause a denial of service and possibly excecute arbitrary code via the (1) SOCKS, (2) RSVP, (3) AFS, or (4) LMP dissectors, which can be caused to core dump.
CVE-2002-0821 1 Ethereal Group 1 Ethereal 2008-09-05 7.5 HIGH N/A
Buffer overflows in Ethereal 0.9.4 and earlier allow remote attackers to cause a denial of service or execute arbitrary code via (1) the BGP dissector, or (2) the WCP dissector.
CVE-2002-0942 1 Lumigent 1 Log Explorer 2008-09-05 7.5 HIGH N/A
Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long arguments to the extended stored procedures (1) xp_logattach_StartProf, (2) xp_logattach_setport, or (3) xp_logattach.
CVE-2002-0922 1 Cgiscript.net 1 Csnews 2008-09-05 5.0 MEDIUM N/A
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.
CVE-2002-0883 1 Compaq 1 Proliant Bl E-class Integrated Administrator Firmware 2008-09-05 7.2 HIGH N/A
Vulnerability in Compaq ProLiant BL e-Class Integrated Administrator 1.0 and 1.10, allows authenticated users with Telnet, SSH, or console access to conduct unauthorized activities.
CVE-2002-1131 1 Squirrelmail 1 Squirrelmail 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.
CVE-2002-0932 1 Luis Bernardo 1 Myhelpdesk 2008-09-05 6.4 MEDIUM N/A
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.
CVE-2002-0933 1 Datalex 1 Bookit Consumer 2008-09-05 7.5 HIGH N/A
Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks.
CVE-2002-1127 1 Digital 1 Osf 1 2008-09-05 7.2 HIGH N/A
Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.
CVE-2002-0934 1 Jon Hedley 1 Alienform2 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) allows remote attackers to read or modify arbitrary files via an illegal character in the middle of a .. (dot dot) sequence in the parameters (1) _browser_out or (2) _out_file.
CVE-2002-0941 1 Ncipher 2 Nforce, Nshield 2008-09-05 4.6 MEDIUM N/A
The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges.
CVE-2002-0806 1 Mozilla 1 Bugzilla 2008-09-05 2.1 LOW N/A
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.
CVE-2002-0891 1 Juniper 1 Netscreen Screenos 2008-09-05 5.0 MEDIUM N/A
The web interface (WebUI) of NetScreen ScreenOS before 2.6.1r8, and certain 2.8.x and 3.0.x versions before 3.0.3r1, allows remote attackers to cause a denial of service (crash) via a long user name.