Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0781 1 Novell 1 Bordermanager 2008-09-05 5.0 MEDIUM N/A
RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a series of carriage returns, which causes proxy.nlm to ABEND.
CVE-2002-0672 1 Pingtel 1 Xpressa 2008-09-05 4.6 MEDIUM N/A
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null.
CVE-2002-0673 1 Pingtel 1 Xpressa 2008-09-05 4.6 MEDIUM N/A
The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In to gain remote access and perform unauthorized actions.
CVE-2002-0703 1 Gisle Aas 1 Digest-md5 2008-09-05 7.5 HIGH N/A
An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data.
CVE-2002-0728 1 Greg Roelofs 1 Libpng 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.
CVE-2002-0780 1 Novell 1 Bordermanager 2008-09-05 5.0 MEDIUM N/A
IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND.
CVE-2002-0770 1 Id Software 1 Quake 2i Server 2008-09-05 5.0 MEDIUM N/A
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say $rcon_password."
CVE-2002-0769 1 Cisco 1 Ata-186 2008-09-05 6.4 MEDIUM N/A
The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass authentication via an HTTP POST request with a single byte, which allows the attackers to (1) obtain the password from the login screen, or (2) reconfigure the adaptor by modifying certain request parameters.
CVE-2002-0768 2 Luke Mewburn, Suse 2 Lukemftp, Suse Linux 2008-09-05 7.5 HIGH N/A
Buffer overflow in lukemftp FTP client in SuSE 6.4 through 8.0, and possibly other operating systems, allows a malicious FTP server to execute arbitrary code via a long PASV command.
CVE-2002-0767 1 Richard Gooch 1 Simpleinit 2008-09-05 7.2 HIGH N/A
simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges.
CVE-2002-0745 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Buffer overflow in uucp in AIX 4.3.3.
CVE-2002-0730 1 Philip Chinery 1 Philip Chinerys Guestbook 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.
CVE-2002-0731 1 Vqsoft 1 Vqserver 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as respond.pl.
CVE-2002-0583 1 Workforceroi 1 Xpede 2008-09-05 5.0 MEDIUM N/A
WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports via a brute force attack.
CVE-2002-0582 1 Workforceroi 1 Xpede 2008-09-05 5.0 MEDIUM N/A
WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote attackers to read the reports by accessing the directory.
CVE-2002-0558 1 Typsoft 1 Typsoft Ftp Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending in wildcard *.* characters.
CVE-2002-0557 1 Openbsd 1 Openbsd 2008-09-05 7.5 HIGH N/A
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to auth_approval().
CVE-2002-0556 1 Deep Forest Software 1 Quik-serv Webserver 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
CVE-2002-0555 1 Ibm 1 Informix Web Datablade 2008-09-05 7.5 HIGH N/A
IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.
CVE-2002-0732 1 Levcgi.com 1 Myguestbook 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments.
CVE-2002-0584 1 Workforceroi 1 Xpede 2008-09-05 5.0 MEDIUM N/A
WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for each new timesheet.
CVE-2002-0764 1 Phorum 1 Phorum 2008-09-05 7.5 HIGH N/A
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands.
CVE-2002-0805 1 Mozilla 1 Bugzilla 2008-09-05 4.6 MEDIUM N/A
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.
CVE-2002-0733 1 Acme Labs 1 Thttpd 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
CVE-2002-0544 1 Aprelium Technologies 1 Abyss Web Server 2008-09-05 7.2 HIGH N/A
Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.
CVE-2002-0543 1 Aprelium Technologies 1 Abyss Web Server 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.
CVE-2002-0541 1 Ibm 1 Tivoli Storage Manager 2008-09-05 7.5 HIGH N/A
Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581.
CVE-2002-0540 1 Nortel 1 Cvx 1800 Multi-service Access Switch 2008-09-05 7.5 HIGH N/A
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.
CVE-2002-0539 1 Demarc Security 1 Puresecure 2008-09-05 10.0 HIGH N/A
Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.
CVE-2002-0537 1 Stepweb 1 Sws 2008-09-05 10.0 HIGH N/A
The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.
CVE-2002-0763 1 Hp 1 Virtualvault 2008-09-05 7.5 HIGH N/A
Vulnerability in administration server for HP VirtualVault 4.5 on HP-UX 11.04 allows remote web servers or privileged external processes to bypass access restrictions and establish connections to the server.
CVE-2002-0503 1 Citrix 1 Nfuse 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
CVE-2002-0580 1 Workforceroi 1 Xpede 2008-09-05 7.5 HIGH N/A
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute force password guessing attacks.
CVE-2002-0483 1 Francisco Burzi 1 Php-nuke 2008-09-05 5.0 MEDIUM N/A
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.
CVE-2002-0750 1 Cgiscript.net 1 Csmailto 2008-09-05 5.0 MEDIUM N/A
CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment field.
CVE-2002-0777 1 Ipswitch 1 Imail 2008-09-05 10.0 HIGH N/A
Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter.
CVE-2002-0487 1 Workforceroi 1 Xpede 2008-09-05 4.6 MEDIUM N/A
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache.
CVE-2002-0515 1 Darren Reed 1 Ipfilter 2008-09-05 5.0 MEDIUM N/A
IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.
CVE-2002-0512 1 Caldera 2 Openlinux Server, Openlinux Workstation 2008-09-05 4.6 MEDIUM N/A
startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries.
CVE-2002-0532 1 Emumail 3 Emumail, Emumail Red Hat Linux, Emumail Unix 2008-09-05 7.2 HIGH N/A
EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters.
CVE-2002-0513 1 Symatec 1 Popper Mod 2008-09-05 10.0 HIGH N/A
The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
CVE-2002-0804 1 Mozilla 1 Bugzilla 2008-09-05 7.5 HIGH N/A
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.
CVE-2002-0498 1 Etnus 1 Totalview 2008-09-05 4.6 MEDIUM N/A
Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users.
CVE-2002-0499 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.
CVE-2002-0550 1 Gcf 1 Dynamic Guestbook 2008-09-05 7.5 HIGH N/A
Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.
CVE-2002-0747 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
Buffer overflow in lsmcode in AIX 4.3.3.
CVE-2002-0514 1 Openbsd 1 Openbsd 2008-09-05 5.0 MEDIUM N/A
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.
CVE-2002-0536 1 Phpgroupware 1 Phpgroupware 2008-09-05 7.5 HIGH N/A
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.
CVE-2002-0776 1 Hosting Controller 1 Hosting Controller 2008-09-05 7.5 HIGH N/A
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
CVE-2002-0752 1 Cgiscript.net 1 Csmailto 2008-09-05 5.0 MEDIUM N/A
CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackers to obtain sensitive information by directly accessing the file.