Vulnerabilities (CVE)

Total 304758 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1449 1 Frederic Tyndiuk 1 Eupload 2008-09-10 7.5 HIGH N/A
eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.
CVE-2002-1280 1 Iss 1 Realsecure Event Collector 2008-09-10 5.0 MEDIUM N/A
Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).
CVE-2002-1395 1 Debian 1 Internet Message 2008-09-10 2.1 LOW N/A
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz.
CVE-2002-1285 1 Suse 1 Suse Linux 2008-09-10 7.2 HIGH N/A
runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.
CVE-2002-1379 1 Openldap 1 Openldap 2008-09-10 7.5 HIGH N/A
OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges.
CVE-2002-1511 2 Att, Tightvnc 2 Vnc, Tightvnc 2008-09-10 5.0 MEDIUM N/A
The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.
CVE-2002-1169 1 Ibm 1 Websphere Caching Proxy Server 2008-09-10 5.0 MEDIUM N/A
IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.
CVE-2002-1213 1 Radiobird Software 1 Webserver 4 All 2008-09-10 5.0 MEDIUM N/A
Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters.
CVE-2002-0978 1 Microsoft 1 File Transfer Manager 2008-09-10 5.0 MEDIUM N/A
Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT and TGN parameters in a call to the "Persist" function.
CVE-2002-0987 1 Caldera 2 Openunix, Unixware 2008-09-10 7.2 HIGH N/A
X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.
CVE-2002-0875 2 Debian, Sgi 3 Debian Linux, Fam, Irix 2008-09-10 2.1 LOW N/A
Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.
CVE-2002-0856 1 Oracle 2 Database Server, Oracle9i 2008-09-10 5.0 MEDIUM N/A
SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.
CVE-2002-0920 1 Cgiscript.net 1 Cspassword 2008-09-10 5.1 MEDIUM N/A
CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed.
CVE-2002-0939 1 Ncipher 1 Mscapi Csp 2008-09-10 4.6 MEDIUM N/A
The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).
CVE-2002-0873 1 L2tpd 1 L2tpd 2008-09-10 5.0 MEDIUM N/A
Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow.
CVE-2002-0981 1 Caldera 2 Openunix, Unixware 2008-09-10 7.2 HIGH N/A
Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line.
CVE-2002-1167 1 Ibm 1 Websphere Caching Proxy Server 2008-09-10 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.
CVE-2002-0948 1 Scripts For Educators 1 Makebook 2008-09-10 7.5 HIGH N/A
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email parameters, which are not properly filtered.
CVE-2002-0852 1 Cisco 1 Vpn Client 2008-09-10 5.0 MEDIUM N/A
Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.
CVE-2002-0874 1 Redhat 1 Interchange 2008-09-10 5.0 MEDIUM N/A
Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.