Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-1018 | 1 Adobe | 1 Adobe Content Server | 2016-10-17 | 5.0 MEDIUM | N/A |
The library feature for Adobe Content Server 3.0 does not verify if a customer has already checked out an eBook, which allows remote attackers to cause a denial of service (resource exhaustion) by checking out the same book multiple times. | |||||
CVE-2002-1019 | 1 Adobe | 1 Adobe Content Server | 2016-10-17 | 5.0 MEDIUM | N/A |
The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook for an arbitrary length of time via a modified loanMin parameter to download.asp. | |||||
CVE-2002-1020 | 1 Adobe | 1 Adobe Content Server | 2016-10-17 | 5.0 MEDIUM | N/A |
The library feature for Adobe Content Server 3.0 allows a remote attacker to check out an eBook even when the maximum number of loans is exceeded by accessing the "Add to bookbag" feature when the server reports that no more copies are available. | |||||
CVE-2002-1037 | 1 Michael Dean | 1 Double Choco Latte | 2016-10-17 | 5.0 MEDIUM | N/A |
Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features. | |||||
CVE-2002-1038 | 1 Michael Dean | 1 Double Choco Latte | 2016-10-17 | 5.0 MEDIUM | N/A |
Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features. | |||||
CVE-2002-1039 | 1 Michael Dean | 1 Double Choco Latte | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to read arbitrary files via .. (dot dot) sequences when downloading files from the Projects: Attachments feature. | |||||
CVE-2002-1051 | 1 Ehud Gavron | 1 Tracesroute | 2016-10-17 | 4.6 MEDIUM | N/A |
Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument. | |||||
CVE-2002-1052 | 1 W3c | 1 Jigsaw | 2016-10-17 | 5.0 MEDIUM | N/A |
Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physical path of the server using two requests to the "aux" device. | |||||
CVE-2002-1059 | 1 Van Dyke Technologies | 1 Securecrt | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string. | |||||
CVE-2002-1068 | 1 D-link | 1 Dp-303 | 2016-10-17 | 5.0 MEDIUM | N/A |
The web server for D-Link DP-300 print server allows remote attackers to cause a denial of service (hang) via a large HTTP POST request. | |||||
CVE-2002-1069 | 1 D-link | 1 Di-804 | 2016-10-17 | 5.0 MEDIUM | N/A |
The remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP addresses or obtain sensitive information via a direct web request to the pages (1) release.htm, (2) Device Status, or (3) Device Information. | |||||
CVE-2002-1091 | 3 Mozilla, Netscape, Opera Software | 3 Mozilla, Navigator, Opera Web Browser | 2016-10-17 | 7.5 HIGH | N/A |
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width. | |||||
CVE-2002-1109 | 1 Amavis | 1 Virus Scanner | 2016-10-17 | 2.1 LOW | N/A |
securetar, as used in AMaViS shell script 0.2.1 and earlier, allows users to cause a denial of service (CPU consumption) via a malformed TAR file, possibly via an incorrect file size parameter. | |||||
CVE-2002-1110 | 1 Mantis | 1 Mantis | 2016-10-17 | 10.0 HIGH | N/A |
Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php. | |||||
CVE-2002-1114 | 1 Mantis | 1 Mantis | 2016-10-17 | 7.5 HIGH | N/A |
config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_include_page, (2) g_top_include_page, (3) g_css_include_file, (4) g_meta_include_file, or (5) a cookie. | |||||
CVE-2002-1115 | 1 Mantis | 1 Mantis | 2016-10-17 | 5.0 MEDIUM | N/A |
Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php. | |||||
CVE-2002-1119 | 1 Python Software Foundation | 1 Python | 2016-10-17 | 4.6 MEDIUM | N/A |
os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack. | |||||
CVE-2002-1121 | 4 Gfi, Network Associates, Roaring Penguin and 1 more | 5 Mailsecurity, Webshield Smtp, Canit and 2 more | 2016-10-17 | 7.5 HIGH | N/A |
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly") and supported in such products as Outlook Express, which allows remote attackers to bypass content filtering, including virus checking, via fragmented emails of the message/partial content type. | |||||
CVE-2002-1125 | 1 Freebsd | 1 Freebsd | 2016-10-17 | 2.1 LOW | N/A |
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory. | |||||
CVE-2002-1126 | 2 Galeon, Mozilla | 2 Galeon Browser, Mozilla | 2016-10-17 | 2.6 LOW | N/A |
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, including manually entered URLs, using the onunload handler. |