Vulnerabilities (CVE)

Total 231915 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0505 1 Cisco 1 Call Manager 2008-09-05 5.0 MEDIUM N/A
Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.
CVE-2002-0503 1 Citrix 1 Nfuse 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
CVE-2002-0454 1 Qualcomm 1 Qpopper 2008-09-05 5.0 MEDIUM N/A
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop.
CVE-2002-0785 1 Aol 1 Instant Messenger 2008-09-05 5.0 MEDIUM N/A
AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow.
CVE-2002-0551 1 Gcf 1 Dynamic Guestbook 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.
CVE-2002-0579 1 Workforceroi 1 Xpede 2008-09-05 7.5 HIGH N/A
WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.
CVE-2002-0676 1 Apple 1 Mac Os X 2008-09-05 7.5 HIGH N/A
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.
CVE-2002-0463 1 Arsc Really Simple Chat 1 Arsc Really Simple Chat 2008-09-05 5.0 MEDIUM N/A
home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message.
CVE-2002-0748 1 National Instruments 1 Labview 2008-09-05 5.0 MEDIUM N/A
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline characters, instead of the expected carriage return/newline combinations.
CVE-2002-0787 1 Critical Path 1 Injoin Directory Server 2008-09-05 7.5 HIGH N/A
Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator via administrator URLs with modified (1) LOCID or (2) OC parameters.
CVE-2002-0481 1 Microsoft 1 Outlook 2008-09-05 5.1 MEDIUM N/A
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function.
CVE-2002-0588 1 Steve Korbett 1 Pvote 2008-09-05 5.0 MEDIUM N/A
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
CVE-2002-0460 1 Bitvise 1 Winsshd 2008-09-05 5.0 MEDIUM N/A
Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of incomplete connections that are not properly terminated, which are not properly freed by SSHd.
CVE-2002-0464 1 Hosting Controller 1 Hosting Controller 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor.asp, (2) folderactions.asp, or (3) editoractions.asp.
CVE-2002-0510 1 Linux 1 Linux Kernel 2008-09-05 5.0 MEDIUM N/A
The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.
CVE-2002-0452 1 Foundrynet 1 Serveriron 2008-09-05 7.5 HIGH N/A
Foundry Networks ServerIron switches do not decode URIs when applying "url-map" rules, which could make it easier for attackers to cause the switch to forward traffic to a different server than intended and exploit vulnerabilities that would otherwise be inaccessible.
CVE-2002-0462 1 Big Sam 1 Big Sam 2008-09-05 6.4 MEDIUM N/A
bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the web server via a displayBegin parameter with a very large number, which leaks the web path in an error message when PHP safe_mode is enabled, or consumes resources when safe_mode is not enabled.
CVE-2002-0524 1 Asp-nuke 1 Asp-nuke 2008-09-05 5.0 MEDIUM N/A
ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, which leak the pathname in an error message.
CVE-2002-0759 1 Bzip 1 Bzip2 2008-09-05 5.0 MEDIUM N/A
bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly other operating systems, does not use the O_EXCL flag to create files during decompression and does not warn the user if an existing file would be overwritten, which could allow attackers to overwrite files via a bzip2 archive.
CVE-2002-0451 1 Phpprojekt 1 Phpprojekt 2008-09-05 7.5 HIGH N/A
filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_path parameter.