2002 CVE Vulnerabilities

2,393 CVEs published in 2002.

CVE IDSeverityCVSSDescription
CVE-2002-1559Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (d...
CVE-2002-1557Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TC...
CVE-2002-1560index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting th...
CVE-2002-1556Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP req...
CVE-2002-1547Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH ...
CVE-2002-1546BRS WebWeaver Web Server 1.01 allows remote attackers to bypass password protections for files and directories via an HT...
CVE-2002-0387Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows re...
CVE-2002-1337Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted addre...
CVE-2002-1510xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth ...
CVE-2002-1511The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to g...
CVE-2002-0842Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracl...
CVE-2002-0841Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0842. Reason: This candidate is a duplicate of...
CVE-2002-1472Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users ...
CVE-2002-1509A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of ...
CVE-2002-0669The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause...
CVE-2002-0036Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of...
CVE-2002-1404Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1348. Reason: This candidate is a reservation ...
CVE-2002-1508slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition d...
CVE-2002-1348w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attac...
CVE-2002-1160The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local ...
CVE-2002-1405CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP...
CVE-2002-1252The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remot...
CVE-2002-1403dhcpcd DHCP client daemon 1.3.22 and earlier allows local users to execute arbitrary code via shell metacharacters that ...
CVE-2002-1390The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbit...
CVE-2002-1402Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local ...

Check if your code is affected by 2002 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now