Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29527 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1516 1 Sgi 1 Irix 2008-09-10 4.6 MEDIUM N/A
rpcbind in SGI IRIX, when using the -w command line switch, allows local users to overwrite arbitrary files via a symlink attack.
CVE-2002-1352 1 Per Magne Knutsen 1 Cartman 2008-09-10 5.0 MEDIUM N/A
Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product prices by changing the price parameter.
CVE-2002-1278 1 Jacques Gelinas 1 Linuxconf 2008-09-10 7.5 HIGH N/A
The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail relay, which allows remote attackers to send Spam email.
CVE-2002-1202 1 Compaq 1 Tru64 2008-09-10 7.5 HIGH N/A
Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.
CVE-2002-1342 1 Smb2www 1 Smb2www 2008-09-10 7.5 HIGH N/A
Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.
CVE-2002-1508 1 Openldap 1 Openldap 2008-09-10 1.2 LOW N/A
slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.
CVE-2002-1212 1 Radiobird Software 1 Webserver 4 All 2008-09-10 5.0 MEDIUM N/A
Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
CVE-2002-1231 1 Caldera 2 Openunix, Unixware 2008-09-10 2.1 LOW N/A
SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc.
CVE-2002-1540 1 Symantec 1 Norton Antivirus 2008-09-10 7.2 HIGH N/A
The client for Symantec Norton AntiVirus Corporate Edition 7.5.x before 7.5.1 Build 62 and 7.6.x before 7.6.1 Build 35a runs winhlp32 with raised privileges, which allows local users to gain privileges by using certain features of winhlp32.
CVE-2002-1194 1 Netbsd 1 Netbsd 2008-09-10 7.5 HIGH N/A
Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.
CVE-2002-1204 1 Netscape 1 Communicator 2008-09-10 5.0 MEDIUM N/A
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.
CVE-2002-1449 1 Frederic Tyndiuk 1 Eupload 2008-09-10 7.5 HIGH N/A
eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.
CVE-2002-1280 1 Iss 1 Realsecure Event Collector 2008-09-10 5.0 MEDIUM N/A
Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).
CVE-2002-1395 1 Debian 1 Internet Message 2008-09-10 2.1 LOW N/A
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz.
CVE-2002-1285 1 Suse 1 Suse Linux 2008-09-10 7.2 HIGH N/A
runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.
CVE-2002-1379 1 Openldap 1 Openldap 2008-09-10 7.5 HIGH N/A
OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges.
CVE-2002-1511 2 Att, Tightvnc 2 Vnc, Tightvnc 2008-09-10 5.0 MEDIUM N/A
The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.
CVE-2002-1169 1 Ibm 1 Websphere Caching Proxy Server 2008-09-10 5.0 MEDIUM N/A
IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.
CVE-2002-1213 1 Radiobird Software 1 Webserver 4 All 2008-09-10 5.0 MEDIUM N/A
Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters.
CVE-2002-0978 1 Microsoft 1 File Transfer Manager 2008-09-10 5.0 MEDIUM N/A
Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.