2,156 vulnerabilities published in 2002
The decompression algorithm in zlib 1.1.3 and earlier, as used in many different utilities and packages, causes inflateE
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service an
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allow
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct br
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files wi
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local user
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to othe
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apach
Off-by-one overflow in the CVS PreservePermissions of rcs.c for CVSD before 1.11.2 allows local users to execute arbitra
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local u
ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signature
Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permission
SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbi
The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addre
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Conte
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and s
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess p
Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same cipherte
Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remo
Off-by-one error in alterMIME 0.1.10 and 0.1.11 allows remote attackers to cause a denial of service (crash) via an x-he
Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code
phpRank 1.8 stores the administrative password in plaintext on the server and in the "ap" cookie, which allows remote at
D-Link DWL-900AP+ Access Point 2.1 and 2.2 allows remote attackers to access the TFTP server without authentication and
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allow
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), w
SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, w
The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which
TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote att
BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that are attached to files o
East-Tec Eraser 2002 does not clear Windows alternate data streams that are attached to files on NTFS file systems, whic
Eraser 5.3 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows a
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which all
SecureClean 3 build 2.0 does not clear Windows alternate data streams that are attached to files on NTFS file systems, w
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use sy
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS),
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrit
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard
NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk wh
The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows loca
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by us
Scan for 2002 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started