Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1034 1 Sun 1 I-runbook 2008-09-05 10.0 HIGH N/A
none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument.
CVE-2002-1064 1 T. Hauck 1 Jana Web Server 2008-09-05 5.0 MEDIUM N/A
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
CVE-2002-0932 1 Luis Bernardo 1 Myhelpdesk 2008-09-05 6.4 MEDIUM N/A
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.
CVE-2002-0931 1 Luis Bernardo 1 Myhelpdesk 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as other users via a (1) Title or (2) Description when a new ticket is created by a support assistant, via the "id" parameter to the index.php script with the (3) tickettime, (4) ticketfiles, or (5) updateticketlog operations, or (6) via the update section when a ticket is edited.
CVE-2002-1065 1 T. Hauck 1 Jana Web Server 2008-09-05 7.5 HIGH N/A
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing.
CVE-2002-1066 1 T. Hauck 1 Jana Web Server 2008-09-05 7.5 HIGH N/A
Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command to the POP3 server, which exceeds the array limits and allows a buffer overflow attack.
CVE-2002-1067 1 Seh 1 Ic9 Pocket Print Server Firmware 2008-09-05 5.0 MEDIUM N/A
Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buffer overflow.
CVE-2002-1070 1 Php-wiki 1 Php-wiki 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.
CVE-2002-1071 1 Zyxel 1 Prestige 2008-09-05 5.0 MEDIUM N/A
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.
CVE-2002-1072 1 Zyxel 1 Prestige 2008-09-05 5.0 MEDIUM N/A
ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.
CVE-2002-1086 1 Visualshapers 1 Ezcontents 2008-09-05 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.
CVE-2002-0930 1 Novell 1 Netware 2008-09-05 5.0 MEDIUM N/A
Format string vulnerability in the FTP server for Novell Netware 6.0 SP1 (NWFTPD) allows remote attackers to cause a denial of service (ABEND) via format strings in the USER command.
CVE-2002-0943 1 Metalinks 1 Metacart2.sql 2008-09-05 6.4 MEDIUM N/A
MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb.
CVE-2002-1087 1 Visualshapers 1 Ezcontents 2008-09-05 5.0 MEDIUM N/A
The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request.
CVE-2002-0929 1 Novell 1 Netware 2008-09-05 5.0 MEDIUM N/A
Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests.
CVE-2002-0928 1 Pirch 1 Pirch Irc 2008-09-05 7.5 HIGH N/A
Buffer overflow in the Pirch 98 IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hyperlink in a channel or private message.
CVE-2002-0926 1 Wolfram Research 1 Webmathematica 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the MSPStoreID parameter.
CVE-2002-0925 1 Matthew Mondor 2 Mmftpd, Mmmail 2008-09-05 7.5 HIGH N/A
Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.
CVE-2002-0923 1 Cgiscript.net 1 Csnews 2008-09-05 7.5 HIGH N/A
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.
CVE-2002-1088 1 Novell 1 Groupwise 2008-09-05 7.5 HIGH N/A
Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
CVE-2002-0942 1 Lumigent 1 Log Explorer 2008-09-05 7.5 HIGH N/A
Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long arguments to the extended stored procedures (1) xp_logattach_StartProf, (2) xp_logattach_setport, or (3) xp_logattach.
CVE-2002-0903 1 Woltlab 1 Burning Board 2008-09-05 7.5 HIGH N/A
register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration, along with predictable new user ID's, which allows remote attackers to hijack new user accounts via a brute force attack on the new user ID and the code value.
CVE-2002-1089 1 Oracle 2 Application Server, Reports 2008-09-05 5.0 MEDIUM N/A
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
CVE-2002-0902 1 Phpbb Group 1 Phpbb 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.
CVE-2002-1090 1 Libesmtp 1 Libesmtp 2008-09-05 7.5 HIGH N/A
Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.
CVE-2002-0901 1 Amanda 1 Amanda 2008-09-05 10.0 HIGH N/A
Multiple buffer overflows in Advanced Maryland Automatic Network Disk Archiver (AMANDA) 2.3.0.4 allow (1) remote attackers to execute arbitrary code via long commands to the amindexd daemon, or certain local users to execute arbitrary code via long command line arguments to the programs (2) amcheck, (3) amgetidx, (4) amtrmidx, (5) createindex-dump, or (6) createindex-gnutar.
CVE-2002-0900 1 Mit 1 Pgp Public Key Server 2008-09-05 7.5 HIGH N/A
Buffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long search argument to the lookup capability.
CVE-2002-1127 1 Digital 1 Osf 1 2008-09-05 7.2 HIGH N/A
Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.
CVE-2002-0899 1 Blueface 1 Falcon Web Server 2008-09-05 7.5 HIGH N/A
Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot).
CVE-2002-1131 1 Squirrelmail 1 Squirrelmail 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php.
CVE-2002-1132 1 Squirrelmail 1 Squirrelmail 2008-09-05 5.0 MEDIUM N/A
SquirrelMail 1.2.7 and earlier allows remote attackers to determine the absolute pathname of the options.php script via a malformed optpage file argument, which generates an error message when the file cannot be included in the script.
CVE-2002-0822 1 Ethereal Group 1 Ethereal 2008-09-05 7.5 HIGH N/A
Ethereal 0.9.4 and earlier allows remote attackers to cause a denial of service and possibly excecute arbitrary code via the (1) SOCKS, (2) RSVP, (3) AFS, or (4) LMP dissectors, which can be caused to core dump.
CVE-2002-0922 1 Cgiscript.net 1 Csnews 2008-09-05 5.0 MEDIUM N/A
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.
CVE-2002-0879 1 Gafware 1 Cfximage 2008-09-05 5.0 MEDIUM N/A
showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.
CVE-2002-0878 1 Logisense 2 Dns Manager System, Hawk-i 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.
CVE-2002-0877 1 Evolvable Corporation 1 Shambala Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in the FTP server for Shambala 4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) LIST (ls) or (2) GET commands.
CVE-2002-0876 1 Evolvable Corporation 1 Shambala Server 2008-09-05 5.0 MEDIUM N/A
Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.
CVE-2002-1124 1 Purity 1 Purity 2008-09-05 7.2 HIGH N/A
Multiple buffer overflows in purity 1-16 allow local users to gain privileges and modify high scores tables.
CVE-2002-0851 1 Isdn4linux 1 Isdn4linux 2008-09-05 7.2 HIGH N/A
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog.
CVE-2002-0835 3 Caldera, Hp, Redhat 4 Openlinux Server, Openlinux Workstation, Secure Os and 1 more 2008-09-05 5.0 MEDIUM N/A
Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (VOIP) phones.
CVE-2002-1157 1 Mod Ssl 1 Mod Ssl 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
CVE-2002-0821 1 Ethereal Group 1 Ethereal 2008-09-05 7.5 HIGH N/A
Buffer overflows in Ethereal 0.9.4 and earlier allow remote attackers to cause a denial of service or execute arbitrary code via (1) the BGP dissector, or (2) the WCP dissector.
CVE-2002-0827 1 Caldera 2 Openunix, Unixware 2008-09-05 7.2 HIGH N/A
Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.
CVE-2002-0825 1 Padl Software 1 Nss Ldap 2008-09-05 7.5 HIGH N/A
Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
CVE-2002-0955 1 Yabb 1 Yabb 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site visitors via script in the num parameter, which is not filtered in the resulting error message.
CVE-2002-0956 1 Iss 1 Blackice Agent 2008-09-05 7.5 HIGH N/A
BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass intended firewall restrictions.
CVE-2002-0957 1 Iss 1 Blackice Agent 2008-09-05 5.0 MEDIUM N/A
The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to cause a denial of service (memory consumption) via a large number of connections to the BlackICE system that consumes more resources than intended by the user.
CVE-2002-0958 1 Ekilat Llc 1 Php\(reactor\) 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in browse.php for PHP(Reactor) 1.2.7 allows remote attackers to execute script as other users via the go parameter in the comments section.
CVE-2002-0959 1 Splatt 1 Splatt Forum 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script.
CVE-2002-0960 1 Voxel 1 Cbms 2008-09-05 7.5 HIGH N/A
Multiple cross-site scripting vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allows remote attackers to execute arbitrary script as other CBMS users.