| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2002-0568 | 0.06 | — | 0.75 | Jul 3, 2002 | Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory. | |||
| CVE-2002-0569 | 0.02 | — | 0.19 | Jul 3, 2002 | Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet). | |||
| CVE-2002-0570 | 0.00 | — | 0.00 | Jul 3, 2002 | The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key. | |||
| CVE-2002-0571 | 0.00 | — | 0.03 | Jul 3, 2002 | Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax. | |||
| CVE-2002-0572 | 0.03 | — | 0.02 | Jul 3, 2002 | FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid… | |||
| CVE-2002-0573 | 0.01 | — | 0.09 | Jul 3, 2002 | Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed. | |||
| CVE-2002-0574 | 0.00 | — | 0.02 | Jul 3, 2002 | Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which prevents the entry from being… | |||
| CVE-2002-0615 | 0.00 | — | 0.06 | Jul 3, 2002 | The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation". | |||
| CVE-2002-0620 | 0.01 | — | 0.12 | Jul 3, 2002 | Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API. | |||
| CVE-2002-0621 | 0.01 | — | 0.17 | Jul 3, 2002 | Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer. | |||
| CVE-2002-0622 | 0.02 | — | 0.19 | Jul 3, 2002 | The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution". | |||
| CVE-2002-0623 | 0.02 | — | 0.20 | Jul 3, 2002 | Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun". | |||
| CVE-2002-0631 | 0.00 | — | 0.00 | Jul 3, 2002 | Unknown vulnerability in nveventd in NetVisualyzer on SGI IRIX 6.5 through 6.5.16 allows local users to write arbitrary files and gain root privileges. | |||
| CVE-2002-0639 | Cri | 0.65 | 9.8 | 0.18 | Jul 3, 2002 | Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication. | ||
| CVE-2002-0640 | 0.00 | — | 0.27 | Jul 3, 2002 | Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication… | |||
| CVE-2002-0651 | 0.01 | — | 0.13 | Jul 3, 2002 | Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers. | |||
| CVE-2002-0652 | 0.04 | — | 0.09 | Jul 3, 2002 | xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs(). | |||
| CVE-2001-1300 | 0.00 | — | 0.02 | Jun 25, 2002 | Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command. | |||
| CVE-2002-0006 | 0.04 | — | 0.08 | Jun 25, 2002 | XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the client response when the… | |||
| CVE-2002-0146 | 0.00 | — | 0.01 | Jun 25, 2002 | fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite memory via a message count that exceeds the boundaries of an array. | |||
| CVE-2002-0312 | 0.00 | — | 0.02 | Jun 25, 2002 | Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. | |||
| CVE-2002-0313 | 0.04 | — | 0.10 | Jun 25, 2002 | Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL. | |||
| CVE-2002-0314 | 0.00 | — | 0.02 | Jun 25, 2002 | fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. | |||
| CVE-2002-0315 | 0.00 | — | 0.02 | Jun 25, 2002 | fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header. | |||
| CVE-2002-0316 | 0.04 | — | 0.09 | Jun 25, 2002 | Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag. | |||
| CVE-2002-0317 | 0.00 | — | 0.01 | Jun 25, 2002 | Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter. | |||
| CVE-2002-0318 | 0.00 | — | 0.01 | Jun 25, 2002 | FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets. | |||
| CVE-2002-0319 | 0.04 | — | 0.07 | Jun 25, 2002 | Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username. | |||
| CVE-2002-0320 | 0.01 | — | 0.07 | Jun 25, 2002 | Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field. | |||
| CVE-2002-0321 | 0.00 | — | 0.03 | Jun 25, 2002 | Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks. | |||
| CVE-2002-0322 | 0.00 | — | 0.02 | Jun 25, 2002 | Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing. | |||
| CVE-2002-0323 | 0.00 | — | 0.01 | Jun 25, 2002 | comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL. | |||
| CVE-2002-0324 | 0.00 | — | 0.03 | Jun 25, 2002 | Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then… | |||
| CVE-2002-0325 | 0.06 | — | 0.38 | Jun 25, 2002 | Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL. | |||
| CVE-2002-0326 | 0.00 | — | 0.02 | Jun 25, 2002 | Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript. | |||
| CVE-2002-0327 | 0.03 | — | 0.01 | Jun 25, 2002 | Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program. | |||
| CVE-2002-0328 | 0.03 | — | 0.05 | Jun 25, 2002 | Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag. | |||
| CVE-2002-0329 | 0.03 | — | 0.05 | Jun 25, 2002 | Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag. | |||
| CVE-2002-0330 | 0.04 | — | 0.08 | Jun 25, 2002 | Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag. | |||
| CVE-2002-0331 | 0.03 | — | 0.03 | Jun 25, 2002 | Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request. | |||
| CVE-2002-0332 | 0.03 | — | 0.05 | Jun 25, 2002 | Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostname that is determined using reverse DNS lookups, (2) a long AUTH string, or (3) certain data in the xtell request. | |||
| CVE-2002-0333 | 0.03 | — | 0.03 | Jun 25, 2002 | Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument. | |||
| CVE-2002-0334 | 0.00 | — | 0.00 | Jun 25, 2002 | xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows local users to modify files via a symlink attack on the .xtell-log file. | |||
| CVE-2002-0335 | 0.04 | — | 0.08 | Jun 25, 2002 | Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request. | |||
| CVE-2002-0336 | 0.03 | — | 0.05 | Jun 25, 2002 | Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters. | |||
| CVE-2002-0337 | 0.00 | — | 0.02 | Jun 25, 2002 | RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files. | |||
| CVE-2002-0338 | 0.03 | — | 0.03 | Jun 25, 2002 | The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name. | |||
| CVE-2002-0339 | 0.00 | — | 0.02 | Jun 25, 2002 | Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length. | |||
| CVE-2002-0340 | 0.00 | — | 0.04 | Jun 25, 2002 | Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via… | |||
| CVE-2002-0341 | 0.00 | — | 0.01 | Jun 25, 2002 | GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter. |
- CVE-2002-0568Jul 3, 2002risk 0.06cvss —epss 0.75
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
- CVE-2002-0569Jul 3, 2002risk 0.02cvss —epss 0.19
Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).
- CVE-2002-0570Jul 3, 2002risk 0.00cvss —epss 0.00
The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.
- CVE-2002-0571Jul 3, 2002risk 0.00cvss —epss 0.03
Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.
- CVE-2002-0572Jul 3, 2002risk 0.03cvss —epss 0.02
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid…
- CVE-2002-0573Jul 3, 2002risk 0.01cvss —epss 0.09
Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.
- CVE-2002-0574Jul 3, 2002risk 0.00cvss —epss 0.02
Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which prevents the entry from being…
- CVE-2002-0615Jul 3, 2002risk 0.00cvss —epss 0.06
The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation".
- CVE-2002-0620Jul 3, 2002risk 0.01cvss —epss 0.12
Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
- CVE-2002-0621Jul 3, 2002risk 0.01cvss —epss 0.17
Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.
- CVE-2002-0622Jul 3, 2002risk 0.02cvss —epss 0.19
The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".
- CVE-2002-0623Jul 3, 2002risk 0.02cvss —epss 0.20
Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".
- CVE-2002-0631Jul 3, 2002risk 0.00cvss —epss 0.00
Unknown vulnerability in nveventd in NetVisualyzer on SGI IRIX 6.5 through 6.5.16 allows local users to write arbitrary files and gain root privileges.
- risk 0.65cvss 9.8epss 0.18
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
- CVE-2002-0640Jul 3, 2002risk 0.00cvss —epss 0.27
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication…
- CVE-2002-0651Jul 3, 2002risk 0.01cvss —epss 0.13
Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.
- CVE-2002-0652Jul 3, 2002risk 0.04cvss —epss 0.09
xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().
- CVE-2001-1300Jun 25, 2002risk 0.00cvss —epss 0.02
Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.
- CVE-2002-0006Jun 25, 2002risk 0.04cvss —epss 0.08
XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the client response when the…
- CVE-2002-0146Jun 25, 2002risk 0.00cvss —epss 0.01
fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite memory via a message count that exceeds the boundaries of an array.
- CVE-2002-0312Jun 25, 2002risk 0.00cvss —epss 0.02
Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
- CVE-2002-0313Jun 25, 2002risk 0.04cvss —epss 0.10
Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.
- CVE-2002-0314Jun 25, 2002risk 0.00cvss —epss 0.02
fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.
- CVE-2002-0315Jun 25, 2002risk 0.00cvss —epss 0.02
fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.
- CVE-2002-0316Jun 25, 2002risk 0.04cvss —epss 0.09
Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag.
- CVE-2002-0317Jun 25, 2002risk 0.00cvss —epss 0.01
Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter.
- CVE-2002-0318Jun 25, 2002risk 0.00cvss —epss 0.01
FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.
- CVE-2002-0319Jun 25, 2002risk 0.04cvss —epss 0.07
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.
- CVE-2002-0320Jun 25, 2002risk 0.01cvss —epss 0.07
Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field.
- CVE-2002-0321Jun 25, 2002risk 0.00cvss —epss 0.03
Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.
- CVE-2002-0322Jun 25, 2002risk 0.00cvss —epss 0.02
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.
- CVE-2002-0323Jun 25, 2002risk 0.00cvss —epss 0.01
comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.
- CVE-2002-0324Jun 25, 2002risk 0.00cvss —epss 0.03
Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then…
- CVE-2002-0325Jun 25, 2002risk 0.06cvss —epss 0.38
Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.
- CVE-2002-0326Jun 25, 2002risk 0.00cvss —epss 0.02
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.
- CVE-2002-0327Jun 25, 2002risk 0.03cvss —epss 0.01
Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.
- CVE-2002-0328Jun 25, 2002risk 0.03cvss —epss 0.05
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.
- CVE-2002-0329Jun 25, 2002risk 0.03cvss —epss 0.05
Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag.
- CVE-2002-0330Jun 25, 2002risk 0.04cvss —epss 0.08
Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag.
- CVE-2002-0331Jun 25, 2002risk 0.03cvss —epss 0.03
Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request.
- CVE-2002-0332Jun 25, 2002risk 0.03cvss —epss 0.05
Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostname that is determined using reverse DNS lookups, (2) a long AUTH string, or (3) certain data in the xtell request.
- CVE-2002-0333Jun 25, 2002risk 0.03cvss —epss 0.03
Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument.
- CVE-2002-0334Jun 25, 2002risk 0.00cvss —epss 0.00
xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows local users to modify files via a symlink attack on the .xtell-log file.
- CVE-2002-0335Jun 25, 2002risk 0.04cvss —epss 0.08
Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request.
- CVE-2002-0336Jun 25, 2002risk 0.03cvss —epss 0.05
Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.
- CVE-2002-0337Jun 25, 2002risk 0.00cvss —epss 0.02
RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files.
- CVE-2002-0338Jun 25, 2002risk 0.03cvss —epss 0.03
The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.
- CVE-2002-0339Jun 25, 2002risk 0.00cvss —epss 0.02
Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.
- CVE-2002-0340Jun 25, 2002risk 0.00cvss —epss 0.04
Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via…
- CVE-2002-0341Jun 25, 2002risk 0.00cvss —epss 0.01
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.