Skip to main content

CWE archive

CWE-264 CVEs

Programmatic archive

5,486 CVEs tagged with CWE-264526 Critical, 1,825 High, 2,660 Medium, 475 Low, 0 Unrated.

CVE-2002-2270

Published Dec 31, 2002

Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2283

Published Dec 31, 2002

Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, wh…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2302

Published Dec 31, 2002

3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2324

Published Dec 31, 2002

The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2327

Published Dec 31, 2002

Unspecified vulnerability in the environmental monitoring subsystem in Solaris 8 running on Sun Fire 280R, V480 and V880 allows local users to cause a denial of service by setting…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2334

Published Dec 31, 2002

Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root progra…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2344

Published Dec 31, 2002

Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2353

Published Dec 31, 2002

tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2356

Published Dec 31, 2002

HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2360

Published Dec 31, 2002

The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary com…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-2361

Published Dec 31, 2002

The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2363

Published Dec 31, 2002

VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2394

Published Dec 31, 2002

InterScan VirusWall 3.6 for Linux and 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 chunked transfer encodin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2395

Published Dec 31, 2002

InterScan VirusWall 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 gzip content encoding.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2405

Published Dec 31, 2002

Check Point FireWall-1 4.1 and Next Generation (NG), with UserAuth configured to proxy HTTP traffic only, allows remote attackers to pass unauthorized HTTPS, FTP and possibly othe…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2407

Published Dec 31, 2002

Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbi…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2425

Published Dec 31, 2002

Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1590

Published Oct 29, 2002

The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1111

Published Oct 4, 2002

print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries for bugs that would otherwise b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0012

Published Feb 13, 2002

Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the P…

CVSS 10.0 · Critical
Buzz score
12.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2002-0013

Published Feb 13, 2002

Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest,…

CVSS 10.0 · Critical
Buzz score
12.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-1371

Published Feb 6, 2002

The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,451-5,475 of 5,486 CVEsPage 219 of 220