2002 CVE Vulnerabilities

2,393 CVEs published in 2002.

CVE IDSeverityCVSSDescription
CVE-2002-1696MEDIUM5.5Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk wh...
CVE-2002-1695Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow r...
CVE-2002-1694Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, w...
CVE-2002-1989Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL re...
CVE-2002-1697HIGH7.5Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same cipherte...
CVE-2002-1699SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and...
CVE-2002-1698Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service ...
CVE-2002-2315Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a deni...
CVE-2002-1745HIGH7.5Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code ...
CVE-2002-1706HIGH7.5Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remo...
CVE-2002-1705Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading...
CVE-2002-2325The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44...
CVE-2002-1707install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows ...
CVE-2002-1709SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly ...
CVE-2002-1708Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as ...
CVE-2002-1976ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode...
CVE-2002-1714Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object o...
CVE-2002-1713MEDIUM5.5The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-...
CVE-2002-1712Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of e...
CVE-2002-1977Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, whic...
CVE-2002-1720SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain pr...
CVE-2002-1717Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1...
CVE-2002-1716The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbi...
CVE-2002-1979WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote at...
CVE-2002-1975MEDIUM5.5Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Securi...

Check if your code is affected by 2002 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now