|
345951
|
5.8 |
MEDIUM
|
fad_solutions
|
drzes_hms
|
Cross-site scripting (XSS) vulnerability in register_domain.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the "Domain…
|
NVD-CWE-Other
|
CVE-2005-4367
|
2008-09-20 13:42 |
2005-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345952
|
7.5 |
HIGH
|
asps
|
shopping_cart
|
Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary…
|
NVD-CWE-Other
|
CVE-2005-4003
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345953
|
7.5 |
HIGH
|
jax_calendar
|
jax_calendar
|
SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter, and possibly the (2) Y and (3) m parameter…
|
NVD-CWE-Other
|
CVE-2005-4008
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345954
|
7.5 |
HIGH
|
php_lite
|
calendar_express
|
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (…
|
NVD-CWE-Other
|
CVE-2005-4009
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345955
|
5.0 |
MEDIUM
|
-
|
-
|
property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message.
|
NVD-CWE-Other
|
CVE-2005-4017
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345956
|
7.5 |
HIGH
|
simplemedia
|
simplebbs
|
SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.
|
CWE-89
SQL Injection
|
CVE-2005-4027
|
2008-09-20 13:41 |
2005-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345957
|
7.2 |
HIGH
|
redhat
|
linux
|
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfa…
|
NVD-CWE-Other
|
CVE-2003-0019
|
2008-09-11 09:05 |
2003-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345958
|
7.2 |
HIGH
|
jean-jacques_sarton
|
mtink
|
Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2003-0034
|
2008-09-11 09:05 |
2003-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345959
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
|
NVD-CWE-Other
|
CVE-2003-0049
|
2008-09-11 09:05 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345960
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debu…
|
NVD-CWE-Other
|
CVE-2003-0088
|
2008-09-11 09:05 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345961
|
5.0 |
MEDIUM
|
oracle
|
oracle8i oracle9i
|
TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.
|
NVD-CWE-Other
|
CVE-2002-1118
|
2008-09-11 09:03 |
2002-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345962
|
7.5 |
HIGH
|
matt_blaze
|
cfs
|
Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2002-0351
|
2008-09-11 09:01 |
2002-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345963
|
2.1 |
LOW
|
sgi
|
irix
|
netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.
|
NVD-CWE-Other
|
CVE-2002-0355
|
2008-09-11 09:01 |
2002-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345964
|
7.2 |
HIGH
|
sgi
|
irix
|
Vulnerability in XFS filesystem reorganizer (fsr_xfs) in SGI IRIX 6.5.10 and earlier allows local users to gain root privileges by overwriting critical system files.
|
NVD-CWE-Other
|
CVE-2002-0356
|
2008-09-11 09:01 |
2002-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345965
|
7.2 |
HIGH
|
sgi
|
irix
|
Unknown vulnerability in rpc.passwd in the nfs.sw.nis subsystem of SGI IRIX 6.5.15 and earlier allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-0357
|
2008-09-11 09:01 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345966
|
5.0 |
MEDIUM
|
martin_roesch
|
snort
|
Snort 1.8.3 does not properly define the minimum ICMP header size, which allows remote attackers to cause a denial of service (crash and core dump) via a malformed ICMP packet.
|
NVD-CWE-Other
|
CVE-2002-0115
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345967
|
2.1 |
LOW
|
palm
|
palm_desktop
|
Apple Palm Desktop 4.0b76 and 4.0b77 creates world-readable backup files and folders when a hotsync is performed, which could allow a local user to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2002-0120
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345968
|
2.1 |
LOW
|
php
|
php
|
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
|
NVD-CWE-Other
|
CVE-2002-0121
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345969
|
5.0 |
MEDIUM
|
siemens
|
3568i_wap
|
Siemens 3568i WAP mobile phones allows remote attackers to cause a denial of service (crash) via an SMS message containing unusual characters.
|
NVD-CWE-Other
|
CVE-2002-0122
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345970
|
7.5 |
HIGH
|
mdg_computer_services
|
web_server_4d_ecommerce
|
MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 and earlier, and possibly 3.5.3, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP re…
|
NVD-CWE-Other
|
CVE-2002-0123
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345971
|
5.0 |
MEDIUM
|
mdg_computer_services
|
web_server_4d_ecommerce
|
MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0124
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345972
|
7.2 |
HIGH
|
clanlib
|
clanlib
|
Buffer overflow in ClanLib library 0.5 may allow local users to execute arbitrary code in games that use the library, such as (1) Super Methane Brothers, (2) Star War, (3) Kwirk, (4) Clankanoid, and …
|
NVD-CWE-Other
|
CVE-2002-0125
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345973
|
7.5 |
HIGH
|
selom_ofori
|
blackmoon_ftp_server
|
Buffer overflow in BlackMoon FTP Server 1.0 through 1.5 allows remote attackers to execute arbitrary code via a long argument to (1) USER, (2) PASS, or (3) CWD.
|
NVD-CWE-Other
|
CVE-2002-0126
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345974
|
7.2 |
HIGH
|
chinput
|
chinput
|
Buffer overflow in Chinput 3.0 allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2002-0132
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345975
|
5.0 |
MEDIUM
|
netopia
|
timbuktu_pro
|
Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420).
|
NVD-CWE-Other
|
CVE-2002-0135
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345976
|
7.5 |
HIGH
|
pi-soft
|
spoonftp
|
Pi-Soft SpoonFTP 1.1 and earlier allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.
|
NVD-CWE-Other
|
CVE-2002-0139
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345977
|
7.5 |
HIGH
|
dnrd
|
dnrd
|
Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute arbitrary code via a long or malformed DNS reply, which is not han…
|
NVD-CWE-Other
|
CVE-2002-0140
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345978
|
4.6 |
MEDIUM
|
enlightenment michael_jennings
|
imlib eterm
|
Buffer overflow in Eterm of Enlightenment Imlib2 1.0.4 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2002-0143
|
2008-09-11 09:00 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345979
|
7.5 |
HIGH
|
stephen_turner
|
analog
|
Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly …
|
NVD-CWE-Other
|
CVE-2002-0166
|
2008-09-11 09:00 |
2002-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345980
|
7.5 |
HIGH
|
enlightenment
|
imlib
|
Imlib before 1.9.13 sometimes uses the NetPBM package to load trusted images, which could allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain weakness…
|
NVD-CWE-Other
|
CVE-2002-0167
|
2008-09-11 09:00 |
2002-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345981
|
7.5 |
HIGH
|
enlightenment
|
imlib
|
Vulnerability in Imlib before 1.9.13 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by manipulating arguments that are passed to malloc, which results in a …
|
NVD-CWE-Other
|
CVE-2002-0168
|
2008-09-11 09:00 |
2002-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345982
|
4.6 |
MEDIUM
|
redhat
|
docbook_stylesheets docbook_utils
|
The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an u…
|
NVD-CWE-Other
|
CVE-2002-0169
|
2008-09-11 09:00 |
2002-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345983
|
7.5 |
HIGH
|
sgi
|
irisconsole
|
IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0171
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345984
|
2.1 |
LOW
|
sgi
|
irix
|
/dev/ipfilter on SGI IRIX 6.5 is installed by /dev/MAKEDEV with insecure default permissions (644), which could allow a local user to cause a denial of service (traffic disruption).
|
NVD-CWE-Other
|
CVE-2002-0172
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345985
|
7.2 |
HIGH
|
sgi
|
irix
|
Buffer overflow in cpr for the eoe.sw.cpr SGI Checkpoint-Restart Software package on SGI IRIX 6.5.10 and earlier may allow local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-0173
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345986
|
7.2 |
HIGH
|
sgi
|
irix
|
nsd on SGI IRIX before 6.5.11 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the nsd.dump file.
|
NVD-CWE-Other
|
CVE-2002-0174
|
2008-09-11 09:00 |
2002-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345987
|
4.6 |
MEDIUM
|
avaya
|
libsafe
|
libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not li…
|
NVD-CWE-Other
|
CVE-2002-0175
|
2008-09-11 09:00 |
2002-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345988
|
4.6 |
MEDIUM
|
avaya
|
libsafe
|
The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not ver…
|
NVD-CWE-Other
|
CVE-2002-0176
|
2008-09-11 09:00 |
2002-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345989
|
6.4 |
MEDIUM
|
acd_incorporated
|
cwpapi
|
GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in oth…
|
NVD-CWE-Other
|
CVE-2002-0196
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345990
|
3.6 |
LOW
|
paintbbs
|
paintbbs
|
PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) …
|
NVD-CWE-Other
|
CVE-2002-0202
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345991
|
5.0 |
MEDIUM
|
nortel
|
alteon_acedirector
|
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with …
|
NVD-CWE-Other
|
CVE-2002-0209
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345992
|
7.2 |
HIGH
|
tolis_group
|
bru
|
setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.
|
NVD-CWE-Other
|
CVE-2002-0210
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345993
|
2.1 |
LOW
|
intel
|
intel_pro_wireless_2011b_lan_usb_device_driver
|
Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allow…
|
NVD-CWE-Other
|
CVE-2002-0214
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345994
|
5.0 |
MEDIUM
|
steve_kneizys
|
agora.cgi
|
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an err…
|
NVD-CWE-Other
|
CVE-2002-0215
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345995
|
5.0 |
MEDIUM
|
xoops
|
xoops
|
userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.
|
NVD-CWE-Other
|
CVE-2002-0216
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345996
|
7.5 |
HIGH
|
xoops
|
xoops
|
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Messa…
|
NVD-CWE-Other
|
CVE-2002-0217
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345997
|
7.2 |
HIGH
|
sas
|
sas_base sas_integration_technologies
|
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a …
|
NVD-CWE-Other
|
CVE-2002-0218
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345998
|
7.2 |
HIGH
|
sas
|
sas_base sas_integration_technologies
|
Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.
|
NVD-CWE-Other
|
CVE-2002-0219
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345999
|
7.5 |
HIGH
|
phpsmssend
|
phpsmssend
|
phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters.
|
NVD-CWE-Other
|
CVE-2002-0220
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346000
|
5.0 |
MEDIUM
|
etype
|
eserv
|
Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from ac…
|
NVD-CWE-Other
|
CVE-2002-0221
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|