Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2002-10-28 CVE-2002-1217 Unspecified vulnerability in Microsoft Internet Explorer 5.5/6.0
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.
network
low complexity
microsoft
7.5
2002-10-28 CVE-2002-1214 Buffer Overflow vulnerability in Microsoft products
Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
network
low complexity
microsoft
7.5
2002-10-28 CVE-2002-1202 Remote Route Daemon vulnerability in HP Tru64 Unspecifed
Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.
network
low complexity
compaq
7.5
2002-10-28 CVE-2002-1200 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Oneidentity Syslog-Ng
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
oneidentity CWE-119
7.5
2002-10-28 CVE-2002-1198 SQL Injection vulnerability in Bugzilla Account Creation
Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.
network
low complexity
mozilla
7.5
2002-10-28 CVE-2002-1197 Unspecified vulnerability in Mozilla Bugzilla
bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.
network
low complexity
mozilla
7.5
2002-10-28 CVE-2002-1196 Unspecified vulnerability in Mozilla Bugzilla
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.
network
low complexity
mozilla
7.5
2002-10-28 CVE-2002-1194 Buffer Overflow vulnerability in NetBSD talkd
Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.
network
low complexity
netbsd
7.5
2002-10-28 CVE-2002-1190 Remote Security vulnerability in Unity Server
Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.
network
low complexity
cisco
7.5
2002-10-28 CVE-2002-1179 Buffer Overflow vulnerability in Microsoft Outlook Express S/MIME
Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.
network
low complexity
microsoft
7.5