2002 CVE Vulnerabilities

2,393 CVEs published in 2002.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2002-1352Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product price...
CVE-2002-1566netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to ...
CVE-2002-1155Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command l...
CVE-2002-1565Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation faul...
CVE-2002-1455Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into we...
CVE-2002-1459Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows...
CVE-2002-1454MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a di...
CVE-2002-1462details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information...
CVE-2002-1460L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by...
CVE-2002-1463Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/120...
CVE-2002-1461Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.
CVE-2002-1564Internet Explorer 5.5 and 6.0 allows remote attackers to steal potentially sensitive information from cookies via a cook...
CVE-2002-1457SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements v...
CVE-2002-1456Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.
CVE-2002-1458Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows ...
CVE-2002-1563stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditio...
CVE-2002-1562Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files...
CVE-2002-1466CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via...
CVE-2002-1464Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or s...
CVE-2002-1482SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote...
CVE-2002-1481savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a den...
CVE-2002-1483db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP requ...
CVE-2002-1477graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shel...
CVE-2002-1476Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with...
CVE-2002-1478Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.

Check if your code is affected by 2002 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now