2002 CVE Vulnerabilities

2,393 CVEs published in 2002.

CVE IDSeverityCVSSDescription
CVE-2002-1907TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET re...
CVE-2002-1908Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request wit...
CVE-2002-2188OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invali...
CVE-2002-2322Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which ...
CVE-2002-2389TheServer 1.74 web server stores server.ini under the web document root with insufficient access control, which allows r...
CVE-2002-2422Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remot...
CVE-2002-1909Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt fi...
CVE-2002-1911ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (C...
CVE-2002-1935Pingtel Xpressa 1.2.5 through 2.0.1 uses predictable (1) Call-ID, (2) CSeq, and (3) "To" and "From" SIP URL values in a ...
CVE-2002-2392Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbit...
CVE-2002-2189Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arb...
CVE-2002-1913phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn vari...
CVE-2002-1916Pirch and RusPirch, when auto-log is enabled, allows remote attackers to cause a denial of service (crash) via a nicknam...
CVE-2002-2190ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attac...
CVE-2002-2324The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" ...
CVE-2002-1917CRLF injection vulnerability in the "User Profile: Send Email" feature in Geeklog 1.35 and 1.3.5sr1 allows remote attack...
CVE-2002-1931Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitra...
CVE-2002-1918Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have...
CVE-2002-2191Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obt...
CVE-2002-2198Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing fro...
CVE-2002-1919SQL injection vulnerability in shopadmin.asp in VP-ASP 4.0 allows remote attackers to execute arbitrary SQL commands and...
CVE-2002-1920Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long ...
CVE-2002-2192Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web ...
CVE-2002-2325The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44...
CVE-2002-2390Buffer overflow in the IDENT daemon (identd) in Trillian 0.6351, 0.725, 0.73, 0.74 and 1.0 pro allows remote attackers t...

Check if your code is affected by 2002 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now