Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2002-08-12 CVE-2002-0695 Buffer Overflow vulnerability in Microsoft products
Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
network
low complexity
microsoft
7.5
2002-08-12 CVE-2002-0684 Remote Security vulnerability in glibc
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.
network
low complexity
gnu isc
7.5
2002-08-12 CVE-2002-0660 Unspecified vulnerability in Greg Roelofs Libpng and Libpng3
Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.
network
low complexity
greg-roelofs
7.5
2002-08-12 CVE-2002-0657 Buffer Overflow vulnerability in Openssl 0.9.7
Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key.
network
low complexity
openssl
7.5
2002-08-12 CVE-2002-0656 Buffer Overflow vulnerability in OpenSSL SSLv3 Session ID
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
network
low complexity
openssl oracle apple
7.5
2002-08-12 CVE-2002-0655 Buffer Overflow vulnerability in OpenSSL ASCII Representation Of Integers
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
openssl oracle apple
7.5
2002-08-12 CVE-2002-0649 Buffer Errors vulnerability in Microsoft Data Engine and SQL Server
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
network
low complexity
microsoft CWE-119
7.5
2002-08-12 CVE-2002-0645 Unspecified vulnerability in Microsoft Data Engine and SQL Server
SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
network
low complexity
microsoft
7.5
2002-08-12 CVE-2002-0644 Unspecified vulnerability in Microsoft Data Engine and SQL Server
Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
network
low complexity
microsoft
7.5
2002-08-12 CVE-2002-0619 Unspecified vulnerability in Microsoft Office 2000/Xp
The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
network
low complexity
microsoft
7.5