Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29911 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-0754 2 Freebsd, Kth 3 Freebsd, Heimdal, Heimdal 2026-06-16 7.2 HIGH N/A
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.
CVE-2002-0753 1 Talentsoft 1 Web\+ Server 2026-06-16 10.0 HIGH N/A
Buffer overflow in Talentsoft Web+ 5.0 allows remote attackers to execute arbitrary code via an HTTP request with a long cookie.
CVE-2002-0752 1 Cgiscript.net 1 Csmailto 2026-06-16 5.0 MEDIUM N/A
CGIscript.net csMailto.cgi program exports feedback to a file that is accessible from the web document root, which could allow remote attackers to obtain sensitive information by directly accessing the file.
CVE-2002-0751 1 Cgiscript.net 1 Csmailto 2026-06-16 7.5 HIGH N/A
CGIscript.net csMailto.cgi program allows remote attackers to use csMailto as a "spam proxy" and send mail to arbitrary users via modified (1) form-to, (2) form-from, and (3) form-results parameters.
CVE-2002-0750 1 Cgiscript.net 1 Csmailto 2026-06-16 5.0 MEDIUM N/A
CGIscript.net csMailto.cgi program allows remote attackers to read arbitrary files by specifying the target filename in the form-attachment field.
CVE-2002-0749 1 Cgiscript.net 1 Csmailto 2026-06-16 7.5 HIGH N/A
CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.
CVE-2002-0748 1 National Instruments 1 Labview 2026-06-16 5.0 MEDIUM N/A
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two newline characters, instead of the expected carriage return/newline combinations.
CVE-2002-0747 1 Ibm 1 Aix 2026-06-16 10.0 HIGH N/A
Buffer overflow in lsmcode in AIX 4.3.3.
CVE-2002-0746 1 Ibm 1 Aix 2026-06-16 10.0 HIGH N/A
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.
CVE-2002-0745 1 Ibm 1 Aix 2026-06-16 10.0 HIGH N/A
Buffer overflow in uucp in AIX 4.3.3.
CVE-2002-0744 1 Ibm 1 Aix 2026-06-16 10.0 HIGH N/A
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
CVE-2002-0743 1 Ibm 1 Aix 2026-06-16 10.0 HIGH N/A
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
CVE-2002-0742 1 Ibm 1 Aix 2026-06-16 10.0 HIGH N/A
Buffer overflow in pioout on AIX 4.3.3.
CVE-2002-0741 1 Psychoid 1 Psybnc 2026-06-16 5.0 MEDIUM N/A
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long password argument and quickly killing the connection, which is not properly terminated by psyBNC.
CVE-2002-0740 1 Slrn Development Team 1 Slrn 2026-06-16 7.2 HIGH N/A
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.
CVE-2002-0739 1 Postnuke Software Foundation 1 Postcalendar 2026-06-16 7.5 HIGH N/A
Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page.
CVE-2002-0738 1 Mhonarc 1 Mhonarc 2026-06-16 7.5 HIGH N/A
MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into smaller pieces, (2) including the script in a SRC argument to an IMG tag, or (3) using "&={script}" syntax.
CVE-2002-0737 1 Sambar 1 Sambar Server 2026-06-16 6.4 MEDIUM N/A
Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character.
CVE-2002-0736 1 Microsoft 1 Backoffice 2026-06-16 10.0 HIGH N/A
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.
CVE-2002-0735 2 C-note, Padl Software 3 Squid Auth Ldap, Nss Ldap, Pam Ldap 2026-06-16 7.5 HIGH N/A
Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.