Skip to main content

Year archive

CVEs published in 2002

Archive summary

2,156 CVEs published in 2002 — 166 Critical, 867 High, 980 Medium, 143 Low, 0 Unrated.

CVE-2002-1571

Published Dec 31, 2002

The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant S…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1572

Published Dec 31, 2002

Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1573

Published Dec 31, 2002

Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1617

Published Dec 31, 2002

Multiple buffer overflows in HP Tru64 UNIX 5.x allow local users to execute arbitrary code via (1) a long -contextDir argument to dtaction, (2) a long -p argument to dtprintinfo,…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1622

Published Dec 31, 2002

Buffer overflow in certain RPC routines in IBM AIX 4.3 may allow attackers to execute arbitrary code, related to a "variable data type."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1623

Published Dec 31, 2002

The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during nego…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1624

Published Dec 31, 2002

Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1625

Published Dec 31, 2002

Macromedia Flash Player 6 does not terminate connections when the user leaves the web page, which allows remote attackers to cause a denial of service (bandwidth, resource, and CP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1626

Published Dec 31, 2002

Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1627

Published Dec 31, 2002

Directory traversal vulnerability in quiz.cgi for Mike Spice Quiz Me! before 0.6 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the quiz parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1628

Published Dec 31, 2002

Directory traversal vulnerability in vote.cgi for Mike Spice Mike's Vote CGI before 1.3 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the type par…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1629

Published Dec 31, 2002

Multi-Tech ProxyServer products MTPSR1-100, MTPSR1-120, MTPSR1-202ST, MTPSR2-201, and MTPSR3-200 ship with a null password, which allows remote attackers to gain administrative pr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1630

Published Dec 31, 2002

The sendmail.jsp sample page in Oracle 9i Application Server (9iAS) allows remote attackers to send arbitrary emails.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1631

Published Dec 31, 2002

SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1632

Published Dec 31, 2002

Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1633

Published Dec 31, 2002

Multiple buffer overflows in QNX 4.25 may allow local users to execute arbitrary code via long command line arguments to (1) sample, (2) ex, (3) du, (4) find, (5) lex, (6) mkdir,…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1634

Published Dec 31, 2002

Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1635

Published Dec 31, 2002

The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1636

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server (9iAS) allows remote attackers to inject arbitrary web script or HTML via the c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1646

Published Dec 31, 2002

SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1647

Published Dec 31, 2002

The quick login feature in Slash Slashcode does not redirect the user to an alternate URL when the wrong password is provided, which makes it easier for remote web sites to guess…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1648

Published Dec 31, 2002

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1649

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in read_body.php in SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary Javascript via a javascript: URL in an IMG tag.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1650

Published Dec 31, 2002

The spell checker plugin (check_me.mod.php) for SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary commands via a modified sqspell_command parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1651

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly du…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 2,156 CVEsPage 1 of 87