LiveActive security incident?Get immediate response
CVE archive

2002 CVE Archive

Browse CVE records published in 2002 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2357 matching CVEs · Page 12 of 48.

Unknown · CVSS Not scored

CVE-2002-2223: Buffer overflow in NetScreen-Remote 8.0 allows remote attackers to cause a denial of service and possibly e...

Buffer overflow in NetScreen-Remote 8.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) large number of payloads, or (3) a long payload.

Published Feb 27, 2007 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-2224: Buffer overflow in PGPFreeware 7.03 running on Windows NT 4.0 SP6 allows remote attackers to cause a denial...

Buffer overflow in PGPFreeware 7.03 running on Windows NT 4.0 SP6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) large number of payloads, or (3) a long payload.

Published Feb 27, 2007 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-2211: BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to con...

BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.

Published May 23, 2006 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-2142: An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebL...

An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the extension.

Published Nov 16, 2005 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-2185: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP m...

The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.

Published Nov 16, 2005 · Updated Aug 8, 2024