LiveActive security incident?Get immediate response
CVE archive

July 2002

Browse CVE records published in July 2002, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 27 of 177 matching CVEs · Page 4 of 4.

Unknown · CVSS Not scored

CVE-2002-0624: Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL S...

Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."

Published Jul 12, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-0637: InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages...

InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Type :", (2) "Content-Transfer-Encoding :", (3) no space before a boundary declaration, or (4) "boundary= ", which is processed by Outlook Express.

Published Jul 4, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-0649: Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Eng...

Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.

Published Jul 26, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-0643: The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss f...

The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."

Published Jul 12, 2002 · Updated Aug 8, 2024