2002 CVE Vulnerabilities

2,393 CVEs published in 2002.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2002-1854Rlaj whois CGI script (whois.cgi) 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in ...
CVE-2002-1895The servlet engine in Jakarta Apache Tomcat 3.3 and 4.0.4, when using IIS and the ajp1.3 connector, allows remote attack...
CVE-2002-1919SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and...
CVE-2002-1934Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 2.0.1 leaks sensitive information during boot-up, which allo...
CVE-2002-1943SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a ...
CVE-2002-1947Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop...
CVE-2002-1890rhmask 1.0-9 in Red Hat Linux 7.1 allows local users to overwrite arbitrary files via a symlink attack on the mask file.
CVE-2002-1889Off-by-one buffer overflow in the context_action function in context.c of Logsurfer 1.41 through 1.5a allows remote atta...
CVE-2002-1892NETGEAR FVS318 running firmware 1.1 stores the username and password in a readable format when a backup of the configura...
CVE-2002-1886TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote att...
CVE-2002-1874astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metachara...
CVE-2002-1887PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute a...
CVE-2002-1876Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid r...
CVE-2002-1871pkgadd in Sun Solaris 2.5.1 through 8 installs files setuid/setgid root if the pkgmap file contains a "?" (question mark...
CVE-2002-1875Entercept Agent 2.5 agent for Windows, released before May 21, 2002, allows local administrative users to obtain the ent...
CVE-2002-1884index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "a...
CVE-2002-1888CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web ...
CVE-2002-1893Cross-site scripting (XSS) vulnerability in ArGoSoft Mail Server Pro 1.8.1.9 allows remote attackers to inject arbitrary...
CVE-2002-1865Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (...
CVE-2002-1870Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow ...
CVE-2002-1897MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, ...
CVE-2002-1873Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a deni...
CVE-2002-1863Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, w...
CVE-2002-1885PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote...
CVE-2002-1864Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitra...

Check if your code is affected by 2002 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now