|
344401
|
1.2 |
LOW
|
tarantella
|
tarantella_enterprise
|
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.
|
NVD-CWE-Other
|
CVE-2002-0296
|
2017-07-11 10:29 |
2002-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344402
|
5.0 |
MEDIUM
|
zero_one_tech
|
p100s
|
Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge.
|
NVD-CWE-Other
|
CVE-2002-0305
|
2017-07-11 10:29 |
2002-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344403
|
10.0 |
HIGH
|
stefan_holmberg
|
admentor
|
admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.
|
NVD-CWE-Other
|
CVE-2002-0308
|
2017-07-11 10:29 |
2002-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344404
|
7.5 |
HIGH
|
netwin
|
webnews
|
Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the userna…
|
NVD-CWE-Other
|
CVE-2002-0310
|
2017-07-11 10:29 |
2002-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344405
|
5.0 |
MEDIUM
|
ecometry
|
sgdynamo
|
Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter.
|
NVD-CWE-Other
|
CVE-2002-0375
|
2017-07-11 10:29 |
2002-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344406
|
5.0 |
MEDIUM
|
vignette
|
storyserver vignette
|
Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double quote) and and '>' characters, which causes the TCL…
|
NVD-CWE-Other
|
CVE-2002-0385
|
2017-07-11 10:29 |
2004-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344407
|
10.0 |
HIGH
|
red-m
|
1050ap_lan_acess_point
|
Buffer overflow in Red-M 1050 (Bluetooth Access Point) management web interface allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long administration pass…
|
NVD-CWE-Other
|
CVE-2002-0393
|
2017-07-11 10:29 |
2002-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344408
|
7.2 |
HIGH
|
workforceroi
|
xpede
|
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0486
|
2017-07-11 10:29 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344409
|
7.2 |
HIGH
|
inn
|
inn
|
Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls.
|
NVD-CWE-Other
|
CVE-2002-0526
|
2017-07-11 10:29 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344410
|
5.0 |
MEDIUM
|
postboard postnuke_software_foundation
|
postboard postnuke
|
Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.
|
NVD-CWE-Other
|
CVE-2002-0535
|
2017-07-11 10:29 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344411
|
5.0 |
MEDIUM
|
oracle
|
application_server application_server_web_cache oracle8i oracle9i
|
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2…
|
CWE-287
Improper Authentication
|
CVE-2002-0563
|
2017-07-11 10:29 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344412
|
7.5 |
HIGH
|
aol
|
instant_messenger
|
AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the i…
|
NVD-CWE-Other
|
CVE-2002-0592
|
2017-07-11 10:29 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344413
|
5.0 |
MEDIUM
|
snapgear
|
snapgear_lite\+_firewall
|
Snapgear Lite+ firewall 1.5.4 and 1.5.3 allows remote attackers to cause a denial of service (crash) via a large number of connections to (1) the HTTP web management port, or (2) the PPTP port.
|
NVD-CWE-Other
|
CVE-2002-0602
|
2017-07-11 10:29 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344414
|
2.1 |
LOW
|
entrust
|
entrust_authority_security_manager
|
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that requi…
|
NVD-CWE-Other
|
CVE-2002-0712
|
2017-07-11 10:29 |
2004-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344415
|
5.0 |
MEDIUM
|
cisco
|
cbos
|
Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to t…
|
NVD-CWE-Other
|
CVE-2002-0886
|
2017-07-11 10:29 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344416
|
5.0 |
MEDIUM
|
irssi
|
irssi
|
IRC client irssi in irssi-text before 0.8.4 allows remote attackers to cause a denial of service (crash) via an IRC channel that has a long topic followed by a certain string, possibly triggering a b…
|
NVD-CWE-Other
|
CVE-2002-0983
|
2017-07-11 10:29 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344417
|
7.5 |
HIGH
|
cisco
|
unity_server
|
Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.
|
NVD-CWE-Other
|
CVE-2002-1190
|
2017-07-11 10:29 |
2002-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344418
|
4.6 |
MEDIUM
|
rogue netbsd
|
rogue netbsd
|
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game sa…
|
NVD-CWE-Other
|
CVE-2002-1192
|
2017-07-11 10:29 |
2002-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344419
|
5.0 |
MEDIUM
|
solarwinds
|
tftp_server
|
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.
|
NVD-CWE-Other
|
CVE-2002-1209
|
2017-07-11 10:29 |
2002-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344420
|
7.5 |
HIGH
|
peter_sandvik
|
simple_web_server
|
Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http:/…
|
NVD-CWE-Other
|
CVE-2002-1238
|
2017-07-11 10:29 |
2002-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344421
|
5.0 |
MEDIUM
|
novell
|
emframe
|
Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.
|
NVD-CWE-Other
|
CVE-2002-1283
|
2017-07-11 10:29 |
2002-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344422
|
7.5 |
HIGH
|
microsoft
|
java_virtual_machine
|
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the dom…
|
NVD-CWE-Other
|
CVE-2002-1286
|
2017-07-11 10:29 |
2002-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344423
|
7.5 |
HIGH
|
macromedia
|
jrun
|
Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a lon…
|
NVD-CWE-Other
|
CVE-2002-1310
|
2017-07-11 10:29 |
2002-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344424
|
5.0 |
MEDIUM
|
linksys
|
befn2ps4 befsr11 befsr41 befsr81 befsru31 befsx41 befvp41 befw11s4 hpro200
|
Buffer overflow in the Web management interface in Linksys BEFW11S4 wireless access point router 2 and BEFSR11, BEFSR41, and BEFSRU31 EtherFast Cable/DSL routers with firmware before 1.43.3 with remo…
|
NVD-CWE-Other
|
CVE-2002-1312
|
2017-07-11 10:29 |
2002-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344425
|
7.5 |
HIGH
|
realnetworks
|
realone_player realplayer
|
Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a lo…
|
NVD-CWE-Other
|
CVE-2002-1321
|
2017-07-11 10:29 |
2002-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344426
|
5.0 |
MEDIUM
|
rational_software
|
clearcase
|
Rational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain packets to port 371, e.g. via nmap.
|
NVD-CWE-Other
|
CVE-2002-1322
|
2017-07-11 10:29 |
2002-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344427
|
6.8 |
MEDIUM
|
bizdesign
|
imagefolio
|
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi…
|
NVD-CWE-Other
|
CVE-2002-1334
|
2017-07-11 10:29 |
2002-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344428
|
5.0 |
MEDIUM
|
microsoft
|
office_web_components
|
The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of…
|
NVD-CWE-Other
|
CVE-2002-1338
|
2017-07-11 10:29 |
2002-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344429
|
6.8 |
MEDIUM
|
squirrelmail
|
squirrelmail
|
Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameter…
|
NVD-CWE-Other
|
CVE-2002-1341
|
2017-07-11 10:29 |
2002-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344430
|
5.0 |
MEDIUM
|
melange
|
melange_chat_system
|
Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretDa…
|
NVD-CWE-Other
|
CVE-2002-1351
|
2017-07-11 10:29 |
2002-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344431
|
5.0 |
MEDIUM
|
intranet-server
|
localweb2000
|
LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.
|
NVD-CWE-Other
|
CVE-2002-1353
|
2017-07-11 10:29 |
2002-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344432
|
5.0 |
MEDIUM
|
typsoft
|
typsoft_ftp_server
|
Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.
|
NVD-CWE-Other
|
CVE-2002-1354
|
2017-07-11 10:29 |
2002-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344433
|
7.5 |
HIGH
|
easy_software_products apple
|
cups mac_os_x
|
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into …
|
NVD-CWE-Other
|
CVE-2002-1368
|
2017-07-11 10:29 |
2002-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344434
|
7.5 |
HIGH
|
openldap
|
openldap
|
Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code via (1) long -t or -r parameters to slurpd, (2) a malicious ldapfilter.conf file…
|
NVD-CWE-Other
|
CVE-2002-1378
|
2017-07-11 10:29 |
2003-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344435
|
7.5 |
HIGH
|
postgresql
|
postgresql
|
Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly t…
|
NVD-CWE-Other
|
CVE-2002-1397
|
2017-07-11 10:29 |
2003-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344436
|
7.5 |
HIGH
|
khaled_mardam-bey
|
mirc
|
Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.
|
NVD-CWE-Other
|
CVE-2002-1456
|
2017-07-11 10:29 |
2003-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344437
|
7.5 |
HIGH
|
immunix
|
immunix
|
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
|
NVD-CWE-Other
|
CVE-2002-1565
|
2017-07-11 10:29 |
2003-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344438
|
5.0 |
MEDIUM
|
netris
|
netris
|
netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to cause a denial of service (crash) via a long string to port 9284.
|
NVD-CWE-Other
|
CVE-2002-1566
|
2017-07-11 10:29 |
2003-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344439
|
7.5 |
HIGH
|
ghostview gv
|
ghostview gv
|
gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file.
|
NVD-CWE-Other
|
CVE-2002-1569
|
2017-07-11 10:29 |
2003-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344440
|
7.5 |
HIGH
|
ucd-snmp
|
ucd-snmp
|
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifi…
|
NVD-CWE-Other
|
CVE-2002-1570
|
2017-07-11 10:29 |
2003-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344441
|
5.0 |
MEDIUM
|
mit
|
cgiemail
|
cgiemail allows remote attackers to use cgiemail as a spam proxy via CRLF injection of encoded newline (%0a) characters in parameters such as "required-subject," which can be used to modify the CC, B…
|
NVD-CWE-Other
|
CVE-2002-1575
|
2017-07-11 10:29 |
2004-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344442
|
7.2 |
HIGH
|
sap
|
sap_db
|
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users to gain privileges with a malicious lserversrv that is called…
|
NVD-CWE-Other
|
CVE-2002-1576
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344443
|
7.5 |
HIGH
|
sap
|
sap_r_3
|
SAP R/3 2.0B to 4.6D installs several clients with default users and passwords, which allows remote attackers to gain privileges via the (1) SAP*, (2) SAPCPIC, (3) DDIC, (4) EARLYWATCH, or (5) TMSADM…
|
NVD-CWE-Other
|
CVE-2002-1577
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344444
|
7.5 |
HIGH
|
sap
|
sap_r_3
|
The default installation of SAP R/3, when using Oracle and SQL*net V2 3.x, 4.x, and 6.10, allows remote attackers to obtain arbitrary, sensitive SAP data by directly connecting to the Oracle database…
|
NVD-CWE-Other
|
CVE-2002-1578
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344445
|
5.0 |
MEDIUM
|
sap
|
sapgui
|
SAP GUI (Sapgui) 4.6D allows remote attackers to cause a denial of service (crash) via a connection to a high-numbered port, which generates an "unknown connection data" error.
|
NVD-CWE-Other
|
CVE-2002-1579
|
2017-07-11 10:29 |
2004-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344446
|
7.5 |
HIGH
|
carnegie_mellon_university
|
cyrus_imap_server
|
Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different …
|
NVD-CWE-Other
|
CVE-2002-1580
|
2017-07-11 10:29 |
2004-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344447
|
5.0 |
MEDIUM
|
sun
|
openwindows
|
Mailtool for OpenWindows 3.6, 3.6.1, and 3.6.2 allows remote attackers to cause a denial of service (mailtool segmentation violation and crash) via a malformed mail attachment.
|
NVD-CWE-Other
|
CVE-2002-1588
|
2017-07-11 10:29 |
2002-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344448
|
7.2 |
HIGH
|
grpck pwck
|
grpck pwck
|
Buffer overflow in (1) grpck and (2) pwck, if installed setuid on a system as recommended in some AIX documentation, may allow local users to gain privileges via a long command line argument.
|
NVD-CWE-Other
|
CVE-2002-1594
|
2017-07-11 10:29 |
2002-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344449
|
7.5 |
HIGH
|
daniel_barron
|
dansguardian
|
DansGuardian before 2.4.5-1 allows remote attackers to bypass content filtering rules via hex-encoded URLs.
|
NVD-CWE-Other
|
CVE-2002-1599
|
2017-07-11 10:29 |
2002-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344450
|
5.1 |
MEDIUM
|
adobe
|
photodeluxe
|
The Connectables feature in Adobe PhotoDeluxe 3.1 prepends the Adobe directory to the CLASSPATH environment variable, which allows applets to run with higher privileges and remote attackers to gain p…
|
NVD-CWE-Other
|
CVE-2002-1601
|
2017-07-11 10:29 |
2002-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|