Total
29527 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-0528 | 1 Watchguard | 1 Soho Firewall | 2008-09-05 | 10.0 HIGH | N/A |
Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules. | |||||
CVE-2002-0547 | 1 Nullsoft | 1 Winamp | 2008-09-05 | 7.5 HIGH | N/A |
Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field of an ID3v2 tag. | |||||
CVE-2002-0586 | 1 Aol | 1 Aol Server | 2008-09-05 | 7.5 HIGH | N/A |
Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via the Error or Notice parameters. | |||||
CVE-2002-0782 | 1 Novell | 1 Bordermanager | 2008-09-05 | 5.0 MEDIUM | N/A |
Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to hosts that do not have a specific route, which may be forwarded to the public interface. | |||||
CVE-2002-0728 | 1 Greg Roelofs | 1 Libpng | 2008-09-05 | 5.0 MEDIUM | N/A |
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk. | |||||
CVE-2002-0761 | 1 Bzip | 1 Bzip2 | 2008-09-05 | 2.1 LOW | N/A |
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended. | |||||
CVE-2002-0479 | 1 Gravity Storm Software | 1 Service Pack Manager 2000 | 2008-09-05 | 7.2 HIGH | N/A |
Gravity Storm Service Pack Manager 2000 creates a hidden share (SPM2000c$) mapped to the C drive, which may allow local users to bypass access restrictions on certain directories in the C drive, such as system32, by accessing them through the hidden share. | |||||
CVE-2002-0787 | 1 Critical Path | 1 Injoin Directory Server | 2008-09-05 | 7.5 HIGH | N/A |
Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator via administrator URLs with modified (1) LOCID or (2) OC parameters. | |||||
CVE-2002-0435 | 1 Gnu | 1 Fileutils | 2008-09-05 | 1.2 LOW | N/A |
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system. | |||||
CVE-2002-0764 | 1 Phorum | 1 Phorum | 2008-09-05 | 7.5 HIGH | N/A |
Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands. | |||||
CVE-2002-0441 | 1 Jerrett Taylor | 1 Php Imglist | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in imlist.php for Php Imglist allows remote attackers to read arbitrary code via a .. (dot dot) in the cwd parameter. | |||||
CVE-2002-0446 | 1 Black Tie Project | 1 Black Tie Project | 2008-09-05 | 5.0 MEDIUM | N/A |
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message. | |||||
CVE-2002-0467 | 2 Ecartis, Listar | 2 Ecartis, Listar | 2008-09-05 | 10.0 HIGH | N/A |
Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c. | |||||
CVE-2002-0556 | 1 Deep Forest Software | 1 Quik-serv Webserver | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. | |||||
CVE-2002-0805 | 1 Mozilla | 1 Bugzilla | 2008-09-05 | 4.6 MEDIUM | N/A |
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code. | |||||
CVE-2002-0589 | 1 Steve Korbett | 1 Pvote | 2008-09-05 | 7.5 HIGH | N/A |
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password. | |||||
CVE-2002-0703 | 1 Gisle Aas | 1 Digest-md5 | 2008-09-05 | 7.5 HIGH | N/A |
An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data. | |||||
CVE-2002-0794 | 1 Freebsd | 1 Freebsd | 2008-09-05 | 5.0 MEDIUM | N/A |
The accept_filter mechanism in FreeBSD 4 through 4.5 does not properly remove entries from the incomplete listen queue when adding a syncache, which allows remote attackers to cause a denial of service (network service availability) via a large number of connection attempts, which fills the queue. | |||||
CVE-2002-0767 | 1 Richard Gooch | 1 Simpleinit | 2008-09-05 | 7.2 HIGH | N/A |
simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges. | |||||
CVE-2002-0756 | 2 Usermin, Webmin | 2 Usermin, Webmin | 2008-09-05 | 7.5 HIGH | N/A |
Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies. |