2002 CVE Vulnerabilities

2,393 CVEs published in 2002.

CVE IDSeverityCVSSDescription
CVE-2002-1476Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with...
CVE-2002-1478Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.
CVE-2002-1479Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions...
CVE-2002-1470SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port...
CVE-2002-1483db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP requ...
CVE-2002-1484CRITICAL9.8DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attem...
CVE-2002-1473Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of ser...
CVE-2002-1482SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote...
CVE-2002-1464Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or s...
CVE-2002-1467Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary...
CVE-2002-1468Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
CVE-2002-1469scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote...
CVE-2002-1465SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tabl...
CVE-2002-1480Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script...
CVE-2002-1466CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via...
CVE-2002-1474Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attack...
CVE-2002-1481savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a den...
CVE-2002-1426HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request ...
CVE-2002-1440The Gateway GS-400 server has a default root password of "0001n" that can not be changed via the administrative interfac...
CVE-2002-1428index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cooki...
CVE-2002-1427The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows ...
CVE-2002-1439Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4....
CVE-2002-1423tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the fi...
CVE-2002-1422admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in th...
CVE-2002-1424Buffer overflow in munpack in mpack 1.5 and earlier allows remote attackers to cause a denial of service and possibly ex...

Check if your code is affected by 2002 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now