LiveActive security incident?Get immediate response
CVE archive

2002 CVE Archive

Browse CVE records published in 2002 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2357 matching CVEs · Page 24 of 48.

Unknown · CVSS Not scored

CVE-2002-1286: The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies a...

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the site that is being visited by the user.

Published Nov 14, 2002 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-1256: The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows...

The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.

Published Sep 1, 2004 · Updated Aug 8, 2024

Unknown · CVSS Not scored

CVE-2002-1233: A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and b...

A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the administrator runs (1) htpasswd or (2) htdigest, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2001-0131.

Published Oct 25, 2002 · Updated Aug 8, 2024