Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-0575 | 1 Openbsd | 1 Openssh | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges. | |||||
CVE-2002-0603 | 1 Snapgear | 1 Snapgear Lite\+ Firewall | 2016-10-17 | 5.0 MEDIUM | N/A |
Snapgear Lite+ firewall 1.5.3 allows remote attackers to cause a denial of service (IPSEC crash) via a zero length packet to UDP port 500. | |||||
CVE-2002-0604 | 1 Snapgear | 1 Snapgear Lite\+ Firewall | 2016-10-17 | 5.0 MEDIUM | N/A |
Snapgear Lite+ firewall 1.5.3 and 1.5.4 allows remote attackers to cause a denial of service (crash) via a large number of packets with malformed IP options. | |||||
CVE-2002-0605 | 1 Macromedia | 1 Flash Player | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in Flash OCX for Macromedia Flash 6 revision 23 (6,0,23,0) allows remote attackers to execute arbitrary code via a long movie parameter. | |||||
CVE-2002-0638 | 3 Hp, Mandrakesoft, Redhat | 5 Secure Os, Mandrake Linux, Mandrake Linux Corporate Server and 2 more | 2016-10-17 | 6.2 MEDIUM | N/A |
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh. | |||||
CVE-2002-0639 | 1 Openbsd | 1 Openssh | 2016-10-17 | 10.0 HIGH | N/A |
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication. | |||||
CVE-2002-0640 | 1 Openbsd | 1 Openssh | 2016-10-17 | 10.0 HIGH | N/A |
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt). | |||||
CVE-2002-0317 | 1 Gator | 1 Gator | 2016-10-17 | 7.5 HIGH | N/A |
Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter. | |||||
CVE-2002-0318 | 1 Freeradius | 1 Freeradius | 2016-10-17 | 5.0 MEDIUM | N/A |
FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets. | |||||
CVE-2002-0319 | 1 Powie | 1 Pforum | 2016-10-17 | 7.5 HIGH | N/A |
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username. | |||||
CVE-2002-0320 | 1 Yahoo | 1 Messenger | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field. | |||||
CVE-2002-0321 | 1 Yahoo | 1 Messenger | 2016-10-17 | 5.0 MEDIUM | N/A |
Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks. | |||||
CVE-2002-0322 | 1 Yahoo | 1 Messenger | 2016-10-17 | 7.5 HIGH | N/A |
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing. | |||||
CVE-2002-0323 | 1 Nombas | 1 Scriptease Webserver | 2016-10-17 | 5.0 MEDIUM | N/A |
comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL. | |||||
CVE-2002-0324 | 1 Noah Gray | 1 Graymatter | 2016-10-17 | 7.5 HIGH | N/A |
Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action. | |||||
CVE-2002-0325 | 1 Working Resources Inc. | 1 Badblue | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL. | |||||
CVE-2002-0326 | 1 Working Resources Inc. | 1 Badblue | 2016-10-17 | 7.5 HIGH | N/A |
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript. | |||||
CVE-2002-0327 | 1 Century Software | 1 Term | 2016-10-17 | 7.2 HIGH | N/A |
Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program. | |||||
CVE-2002-0328 | 1 Ikonboard.com | 1 Ikonboard | 2016-10-17 | 7.5 HIGH | N/A |
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag. | |||||
CVE-2002-0329 | 1 Snitz Communications | 1 Snitz Forums 2000 | 2016-10-17 | 7.5 HIGH | N/A |
Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag. |