2002 CVE Vulnerabilities

2,393 CVEs published in 2002.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2002-0387Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows re...
CVE-2002-1337Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted addre...
CVE-2002-1511The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to g...
CVE-2002-0842Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracl...
CVE-2002-1510xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth ...
CVE-2002-0841Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0842. Reason: This candidate is a duplicate of...
CVE-2002-1472Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users ...
CVE-2002-1509A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of ...
CVE-2002-1404Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1348. Reason: This candidate is a reservation ...
CVE-2002-0669The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows administrators to cause...
CVE-2002-0036Integer signedness error in MIT Kerberos V5 ASN.1 decoder before krb5 1.2.5 allows remote attackers to cause a denial of...
CVE-2002-1508slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition d...
CVE-2002-1348w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attac...
CVE-2002-1160The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local ...
CVE-2002-1405CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP...
CVE-2002-1252The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remot...
CVE-2002-1390The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbit...
CVE-2002-1402Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local ...
CVE-2002-1403dhcpcd DHCP client daemon 1.3.22 and earlier allows local users to execute arbitrary code via shell metacharacters that ...
CVE-2002-1401Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for Pos...
CVE-2002-1391Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of service and possibl...
CVE-2002-1392faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to m...
CVE-2002-1394Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to...
CVE-2002-1393Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a she...
CVE-2002-1397Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of servic...

Check if your code is affected by 2002 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now