LiveActive security incident?Get immediate response
CVE archive

June 2002

Browse CVE records published in June 2002, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 48 of 548 matching CVEs · Page 11 of 11.

Unknown · CVSS Not scored

CVE-2002-0031: Buffer overflows in Yahoo!

Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend.

Published Jun 11, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-0082: The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does...

The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session.

Published Jun 25, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-0018: In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a...

In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.

Published Jun 25, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-0027: Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the addres...

Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.

Published Jun 25, 2002 · Updated Aug 8, 2024