| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2002-2277 | 0.00 | — | 0.01 | Dec 31, 2002 | SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_file, (4) $BD_Tab_liens, (5) $BD_Tab_faq, or (6) $chemin variables. | |||
| CVE-2002-2278 | 0.00 | — | 0.01 | Dec 31, 2002 | Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables. | |||
| CVE-2002-2279 | 0.00 | — | 0.02 | Dec 31, 2002 | Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions. | |||
| CVE-2002-2280 | 0.00 | — | 0.00 | Dec 31, 2002 | syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server. | |||
| CVE-2002-2281 | 0.04 | — | 0.10 | Dec 31, 2002 | Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler. | |||
| CVE-2002-2282 | 0.00 | — | 0.00 | Dec 31, 2002 | McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs. | |||
| CVE-2002-2283 | 0.00 | — | 0.02 | Dec 31, 2002 | Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users. | |||
| CVE-2002-2284 | 0.00 | — | 0.02 | Dec 31, 2002 | Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes. | |||
| CVE-2002-2285 | 0.00 | — | 0.02 | Dec 31, 2002 | eTrust InoculateIT 6.0 with the "Incremental Scan" option enabled may certify that a file is free of viruses before the file has been completely downloaded, which allows remote attackers to bypass virus detection. | |||
| CVE-2002-2286 | 0.00 | — | 0.01 | Dec 31, 2002 | The parse-get function in utils.c for apt-www-proxy 0.1 allows remote attackers to cause a denial of service (crash) via an empty HTTP request, which causes a null dereference. | |||
| CVE-2002-2287 | 0.03 | — | 0.02 | Dec 31, 2002 | PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. | |||
| CVE-2002-2288 | 0.03 | — | 0.02 | Dec 31, 2002 | Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message. | |||
| CVE-2002-2289 | 0.00 | — | 0.01 | Dec 31, 2002 | soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords. | |||
| CVE-2002-2290 | 0.00 | — | 0.02 | Dec 31, 2002 | Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges. | |||
| CVE-2002-2291 | 0.00 | — | 0.02 | Dec 31, 2002 | Calisto Internet Talker 0.04 and earlier allows remote attackers to cause a denial of service (hang) via a long request, possibly triggering a buffer overflow. | |||
| CVE-2002-2292 | 0.00 | — | 0.02 | Dec 31, 2002 | Directory traversal vulnerability in Remote Console Applet in Halycon Software iASP 1.0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request to port 9095. | |||
| CVE-2002-2293 | 0.00 | — | 0.00 | Dec 31, 2002 | Webshots Desktop screensaver allows local users to bypass the password on the screensaver by pressing CTRL-ALT-DELETE and (1) hitting the cancel button or (2) killing the screensaver from the task manager. | |||
| CVE-2002-2294 | 0.00 | — | 0.02 | Dec 31, 2002 | Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed… | |||
| CVE-2002-2295 | 0.04 | — | 0.07 | Dec 31, 2002 | Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an off-by-one buffer overflow, or (2) a long method name in an… | |||
| CVE-2002-2296 | 0.03 | — | 0.01 | Dec 31, 2002 | Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter. | |||
| CVE-2002-2297 | 0.00 | — | 0.01 | Dec 31, 2002 | PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter. | |||
| CVE-2002-2298 | 0.03 | — | 0.02 | Dec 31, 2002 | PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter. | |||
| CVE-2002-2299 | 0.00 | — | 0.01 | Dec 31, 2002 | PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter. | |||
| CVE-2002-2300 | — | 0.03 | — | 0.05 | Dec 31, 2002 | Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command. | ||
| CVE-2002-2301 | 0.00 | — | 0.00 | Dec 31, 2002 | Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database. | |||
| CVE-2002-2302 | 0.00 | — | 0.01 | Dec 31, 2002 | 3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field. | |||
| CVE-2002-2303 | 0.00 | — | 0.01 | Dec 31, 2002 | 3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data. | |||
| CVE-2002-2304 | 0.03 | — | 0.01 | Dec 31, 2002 | SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter. | |||
| CVE-2002-2305 | 0.00 | — | 0.01 | Dec 31, 2002 | SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands via the (1) agentname or (2) agentpassword parameter. | |||
| CVE-2002-2306 | 0.03 | — | 0.03 | Dec 31, 2002 | Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages. | |||
| CVE-2002-2307 | 0.00 | — | 0.02 | Dec 31, 2002 | The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20. | |||
| CVE-2002-2308 | 0.00 | — | 0.01 | Dec 31, 2002 | Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself. | |||
| CVE-2002-2309 | 0.03 | — | 0.04 | Dec 31, 2002 | php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments. | |||
| CVE-2002-2310 | 0.00 | — | 0.01 | Dec 31, 2002 | ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords. | |||
| CVE-2002-2311 | 0.01 | — | 0.10 | Dec 31, 2002 | Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the… | |||
| CVE-2002-2312 | 0.03 | — | 0.02 | Dec 31, 2002 | Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. | |||
| CVE-2002-2313 | 0.00 | — | 0.01 | Dec 31, 2002 | Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedded .mhtml file with ActiveX controls that execute a second embedded program,… | |||
| CVE-2002-2314 | 0.04 | — | 0.09 | Dec 31, 2002 | Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail. | |||
| CVE-2002-2315 | 0.04 | — | 0.10 | Dec 31, 2002 | Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router. | |||
| CVE-2002-2316 | 0.00 | — | 0.01 | Dec 31, 2002 | Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network information by… | |||
| CVE-2002-2317 | 0.00 | — | 0.02 | Dec 31, 2002 | Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumption) via an unknown method. | |||
| CVE-2002-2318 | 0.03 | — | 0.01 | Dec 31, 2002 | Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages. | |||
| CVE-2002-2319 | 0.03 | — | 0.02 | Dec 31, 2002 | Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3. | |||
| CVE-2002-2320 | 0.00 | — | 0.01 | Dec 31, 2002 | MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3. | |||
| CVE-2002-2321 | 0.03 | — | 0.01 | Dec 31, 2002 | Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter. | |||
| CVE-2002-2322 | 0.00 | — | 0.01 | Dec 31, 2002 | Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords. | |||
| CVE-2002-2323 | Hig | 0.49 | 7.5 | 0.02 | Dec 31, 2002 | Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions. | ||
| CVE-2002-2324 | 0.00 | — | 0.02 | Dec 31, 2002 | The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted files and modify… | |||
| CVE-2002-2325 | 0.03 | — | 0.03 | Dec 31, 2002 | The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field. | |||
| CVE-2002-2326 | 0.00 | — | 0.01 | Dec 31, 2002 | The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic. |
- CVE-2002-2277Dec 31, 2002risk 0.00cvss —epss 0.01
SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_file, (4) $BD_Tab_liens, (5) $BD_Tab_faq, or (6) $chemin variables.
- CVE-2002-2278Dec 31, 2002risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables.
- CVE-2002-2279Dec 31, 2002risk 0.00cvss —epss 0.02
Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions.
- CVE-2002-2280Dec 31, 2002risk 0.00cvss —epss 0.00
syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.
- CVE-2002-2281Dec 31, 2002risk 0.04cvss —epss 0.10
Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler.
- CVE-2002-2282Dec 31, 2002risk 0.00cvss —epss 0.00
McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs.
- CVE-2002-2283Dec 31, 2002risk 0.00cvss —epss 0.02
Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users.
- CVE-2002-2284Dec 31, 2002risk 0.00cvss —epss 0.02
Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.
- CVE-2002-2285Dec 31, 2002risk 0.00cvss —epss 0.02
eTrust InoculateIT 6.0 with the "Incremental Scan" option enabled may certify that a file is free of viruses before the file has been completely downloaded, which allows remote attackers to bypass virus detection.
- CVE-2002-2286Dec 31, 2002risk 0.00cvss —epss 0.01
The parse-get function in utils.c for apt-www-proxy 0.1 allows remote attackers to cause a denial of service (crash) via an empty HTTP request, which causes a null dereference.
- CVE-2002-2287Dec 31, 2002risk 0.03cvss —epss 0.02
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.
- CVE-2002-2288Dec 31, 2002risk 0.03cvss —epss 0.02
Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.
- CVE-2002-2289Dec 31, 2002risk 0.00cvss —epss 0.01
soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.
- CVE-2002-2290Dec 31, 2002risk 0.00cvss —epss 0.02
Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.
- CVE-2002-2291Dec 31, 2002risk 0.00cvss —epss 0.02
Calisto Internet Talker 0.04 and earlier allows remote attackers to cause a denial of service (hang) via a long request, possibly triggering a buffer overflow.
- CVE-2002-2292Dec 31, 2002risk 0.00cvss —epss 0.02
Directory traversal vulnerability in Remote Console Applet in Halycon Software iASP 1.0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request to port 9095.
- CVE-2002-2293Dec 31, 2002risk 0.00cvss —epss 0.00
Webshots Desktop screensaver allows local users to bypass the password on the screensaver by pressing CTRL-ALT-DELETE and (1) hitting the cancel button or (2) killing the screensaver from the task manager.
- CVE-2002-2294Dec 31, 2002risk 0.00cvss —epss 0.02
Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed…
- CVE-2002-2295Dec 31, 2002risk 0.04cvss —epss 0.07
Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an off-by-one buffer overflow, or (2) a long method name in an…
- CVE-2002-2296Dec 31, 2002risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.
- CVE-2002-2297Dec 31, 2002risk 0.00cvss —epss 0.01
PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
- CVE-2002-2298Dec 31, 2002risk 0.03cvss —epss 0.02
PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
- CVE-2002-2299Dec 31, 2002risk 0.00cvss —epss 0.01
PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
- CVE-2002-2300Dec 31, 2002risk 0.03cvss —epss 0.05
Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command.
- CVE-2002-2301Dec 31, 2002risk 0.00cvss —epss 0.00
Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database.
- CVE-2002-2302Dec 31, 2002risk 0.00cvss —epss 0.01
3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field.
- CVE-2002-2303Dec 31, 2002risk 0.00cvss —epss 0.01
3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.
- CVE-2002-2304Dec 31, 2002risk 0.03cvss —epss 0.01
SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.
- CVE-2002-2305Dec 31, 2002risk 0.00cvss —epss 0.01
SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands via the (1) agentname or (2) agentpassword parameter.
- CVE-2002-2306Dec 31, 2002risk 0.03cvss —epss 0.03
Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages.
- CVE-2002-2307Dec 31, 2002risk 0.00cvss —epss 0.02
The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20.
- CVE-2002-2308Dec 31, 2002risk 0.00cvss —epss 0.01
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself.
- CVE-2002-2309Dec 31, 2002risk 0.03cvss —epss 0.04
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
- CVE-2002-2310Dec 31, 2002risk 0.00cvss —epss 0.01
ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.
- CVE-2002-2311Dec 31, 2002risk 0.01cvss —epss 0.10
Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the…
- CVE-2002-2312Dec 31, 2002risk 0.03cvss —epss 0.02
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.
- CVE-2002-2313Dec 31, 2002risk 0.00cvss —epss 0.01
Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedded .mhtml file with ActiveX controls that execute a second embedded program,…
- CVE-2002-2314Dec 31, 2002risk 0.04cvss —epss 0.09
Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.
- CVE-2002-2315Dec 31, 2002risk 0.04cvss —epss 0.10
Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router.
- CVE-2002-2316Dec 31, 2002risk 0.00cvss —epss 0.01
Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network information by…
- CVE-2002-2317Dec 31, 2002risk 0.00cvss —epss 0.02
Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumption) via an unknown method.
- CVE-2002-2318Dec 31, 2002risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.
- CVE-2002-2319Dec 31, 2002risk 0.03cvss —epss 0.02
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.
- CVE-2002-2320Dec 31, 2002risk 0.00cvss —epss 0.01
MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.
- CVE-2002-2321Dec 31, 2002risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter.
- CVE-2002-2322Dec 31, 2002risk 0.00cvss —epss 0.01
Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.
- risk 0.49cvss 7.5epss 0.02
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.
- CVE-2002-2324Dec 31, 2002risk 0.00cvss —epss 0.02
The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted files and modify…
- CVE-2002-2325Dec 31, 2002risk 0.03cvss —epss 0.03
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.
- CVE-2002-2326Dec 31, 2002risk 0.00cvss —epss 0.01
The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.