2002 CVE Vulnerabilities

2,393 CVEs published in 2002.

CVE IDSeverityCVSSDescription
CVE-2002-2018sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which...
CVE-2002-2017sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to ref...
CVE-2002-2016User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arb...
CVE-2002-2015PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and po...
CVE-2002-2014Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests...
CVE-2002-2268Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
CVE-2002-2012Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpecte...
CVE-2002-2011Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote a...
CVE-2002-2010Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attacke...
CVE-2002-2362Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary...
CVE-2002-2009Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) ...
CVE-2002-2008Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource t...
CVE-2002-2007The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system informatio...
CVE-2002-2006The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the in...
CVE-2002-2005Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain acc...
CVE-2002-2004portmapper in Compaq Tru64 4.0G and 5.0A allows remote attackers to cause a denial of service via a flood of packets.
CVE-2002-2003ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via cert...
CVE-2002-2002Buffer overflow in libc in Compaq Tru64 4.0F, 5.0, 5.1 and 5.1A allows attackers to execute arbitrary code via long (1) ...
CVE-2002-2001jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbi...
CVE-2002-2000ACMS 4.3 and 4.4 in OpenVMS Alpha 7.2 and 7.3 does not properly use process privileges, which allows attackers to access...
CVE-2002-1999HP Praesidium Webproxy 1.0 running on HP-UX 11.04 VVOS could allow remote attackers to cause Webproxy to forward request...
CVE-2002-2074SQL injection vulnerability in Mailidx before 20020105 allows remote attackers to execute arbitrary SQL commands via the...
CVE-2002-1997ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email att...
CVE-2002-1996Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web sc...
CVE-2002-2075ICQ 2001a and 2002b allows remote attackers to cause a denial of service (memory consumption and hang) via a contact mes...

Check if your code is affected by 2002 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now