|
346201
|
7.5 |
HIGH
|
cgiscript.net
|
csnews
|
CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability.
|
NVD-CWE-Other
|
CVE-2002-0924
|
2008-09-11 04:13 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346202
|
4.6 |
MEDIUM
|
ncipher
|
mscapi_csp
|
The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protecti…
|
NVD-CWE-Other
|
CVE-2002-0939
|
2008-09-11 04:13 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346203
|
4.6 |
MEDIUM
|
ncipher
|
mscapi_csp
|
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lowe…
|
NVD-CWE-Other
|
CVE-2002-0940
|
2008-09-11 04:13 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346204
|
7.5 |
HIGH
|
scripts_for_educators
|
makebook
|
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email para…
|
NVD-CWE-Other
|
CVE-2002-0948
|
2008-09-11 04:13 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346205
|
7.5 |
HIGH
|
microsoft
|
file_transfer_manager
|
Buffer overflow in Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to execute arbitrary code via a long TS value.
|
NVD-CWE-Other
|
CVE-2002-0977
|
2008-09-11 04:13 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346206
|
5.0 |
MEDIUM
|
microsoft
|
file_transfer_manager
|
Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT …
|
NVD-CWE-Other
|
CVE-2002-0978
|
2008-09-11 04:13 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346207
|
7.2 |
HIGH
|
caldera
|
unixware openunix
|
Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line.
|
NVD-CWE-Other
|
CVE-2002-0981
|
2008-09-11 04:13 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346208
|
7.5 |
HIGH
|
light
|
light
|
The IRC script included in Light 2.7.x before 2.7.30p5, and 2.8.x before 2.8pre10, running EPIC allows remote attackers to execute arbitrary code if the user joins a channel whose topic includes EPIC…
|
NVD-CWE-Other
|
CVE-2002-0984
|
2008-09-11 04:13 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346209
|
7.2 |
HIGH
|
caldera
|
unixware openunix
|
X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0987
|
2008-09-11 04:13 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346210
|
10.0 |
HIGH
|
caldera
|
unixware openunix
|
Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities.
|
NVD-CWE-Other
|
CVE-2002-0988
|
2008-09-11 04:13 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346211
|
7.5 |
HIGH
|
iss
|
internet_scanner
|
Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers to execute arbitrary code via a long web server response.
|
NVD-CWE-Other
|
CVE-2002-1122
|
2008-09-11 04:13 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346212
|
7.2 |
HIGH
|
digital
|
osf_1 ultrix
|
Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.
|
NVD-CWE-Other
|
CVE-2002-1128
|
2008-09-11 04:13 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346213
|
5.0 |
MEDIUM
|
gnu
|
glibc
|
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a D…
|
NVD-CWE-Other
|
CVE-2002-1146
|
2008-09-11 04:13 |
2002-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346214
|
6.8 |
MEDIUM
|
ibm
|
websphere_caching_proxy_server
|
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-1167
|
2008-09-11 04:13 |
2002-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346215
|
6.8 |
MEDIUM
|
ibm
|
websphere_caching_proxy_server
|
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that …
|
NVD-CWE-Other
|
CVE-2002-1168
|
2008-09-11 04:13 |
2002-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346216
|
3.7 |
LOW
|
sun
|
cobalt_raq_2 cobalt_raq_3i cobalt_raq_4
|
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, follo…
|
NVD-CWE-Other
|
CVE-2002-0430
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346217
|
7.5 |
HIGH
|
trend_micro
|
interscan_viruswall
|
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header s…
|
NVD-CWE-Other
|
CVE-2002-0440
|
2008-09-11 04:12 |
2002-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346218
|
10.0 |
HIGH
|
talentsoft
|
web\+_server
|
Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe.
|
NVD-CWE-Other
|
CVE-2002-0450
|
2008-09-11 04:12 |
2002-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346219
|
5.1 |
MEDIUM
|
novell
|
web_search
|
Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter.
|
NVD-CWE-Other
|
CVE-2002-0530
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346220
|
7.5 |
HIGH
|
kth luke_mewburn
|
kth_kerberos lukemftp
|
Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.
|
NVD-CWE-Other
|
CVE-2002-0600
|
2008-09-11 04:12 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346221
|
7.2 |
HIGH
|
sgi
|
irix
|
Unknown vulnerability in nveventd in NetVisualyzer on SGI IRIX 6.5 through 6.5.16 allows local users to write arbitrary files and gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-0631
|
2008-09-11 04:12 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346222
|
5.0 |
MEDIUM
|
sgi
|
irix
|
Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server.
|
NVD-CWE-Other
|
CVE-2002-0632
|
2008-09-11 04:12 |
2002-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346223
|
7.5 |
HIGH
|
openssl oracle apple
|
openssl application_server corporate_time_outlook_connector http_server mac_os_x
|
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and p…
|
NVD-CWE-Other
|
CVE-2002-0655
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346224
|
7.5 |
HIGH
|
openssl oracle apple
|
openssl application_server corporate_time_outlook_connector http_server mac_os_x
|
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SS…
|
NVD-CWE-Other
|
CVE-2002-0656
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346225
|
7.5 |
HIGH
|
openssl
|
openssl
|
Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key.
|
NVD-CWE-Other
|
CVE-2002-0657
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346226
|
5.0 |
MEDIUM
|
openssl oracle apple
|
openssl application_server corporate_time_outlook_connector http_server mac_os_x
|
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
|
NVD-CWE-Other
|
CVE-2002-0659
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346227
|
7.5 |
HIGH
|
symantec
|
norton_internet_security norton_personal_firewall
|
Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbit…
|
NVD-CWE-Other
|
CVE-2002-0663
|
2008-09-11 04:12 |
2002-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346228
|
5.0 |
MEDIUM
|
frees_wan apple freebsd netbsd global_technology_associates nec
|
frees_wan mac_os_x mac_os_x_server freebsd netbsd gnat_box_firmware bluefire_ix1035_router ix1010 ix1011 ix1020 ix1050 ix2010
|
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via s…
|
NVD-CWE-Other
|
CVE-2002-0666
|
2008-09-11 04:12 |
2002-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346229
|
10.0 |
HIGH
|
pingtel
|
xpressa
|
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.
|
NVD-CWE-Other
|
CVE-2002-0667
|
2008-09-11 04:12 |
2002-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346230
|
4.6 |
MEDIUM
|
pingtel
|
xpressa
|
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone.
|
NVD-CWE-Other
|
CVE-2002-0675
|
2008-09-11 04:12 |
2002-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346231
|
7.5 |
HIGH
|
suse
|
suse_linux
|
ifup-dhcp script in the sysconfig package for SuSE 8.0 allows remote attackers to execute arbitrary commands via spoofed DHCP responses, which are stored and executed in a file.
|
NVD-CWE-Other
|
CVE-2002-0758
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346232
|
7.2 |
HIGH
|
suse
|
suse_linux
|
shadow package in SuSE 8.0 allows local users to destroy the /etc/passwd and /etc/shadow files or assign extra group privileges to some users by changing filesize limits before calling programs that …
|
NVD-CWE-Other
|
CVE-2002-0762
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346233
|
7.5 |
HIGH
|
openbsd
|
openssh openbsd
|
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password.
|
NVD-CWE-Other
|
CVE-2002-0765
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346234
|
7.2 |
HIGH
|
openbsd
|
openbsd
|
OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1,…
|
NVD-CWE-Other
|
CVE-2002-0766
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346235
|
2.1 |
LOW
|
ibm
|
aix
|
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0790
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346236
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.
|
NVD-CWE-Other
|
CVE-2002-0803
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346237
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) fiel…
|
NVD-CWE-Other
|
CVE-2002-0807
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346238
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to bugl…
|
NVD-CWE-Other
|
CVE-2002-0811
|
2008-09-11 04:12 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346239
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as…
|
NVD-CWE-Other
|
CVE-2002-0008
|
2008-09-11 04:11 |
2002-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346240
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pul…
|
NVD-CWE-Other
|
CVE-2002-0009
|
2008-09-11 04:11 |
2002-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346241
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean cha…
|
NVD-CWE-Other
|
CVE-2002-0010
|
2008-09-11 04:11 |
2002-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346242
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.
|
NVD-CWE-Other
|
CVE-2002-0011
|
2008-09-11 04:11 |
2002-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346243
|
7.5 |
HIGH
|
isc astaro
|
bind security_linux
|
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DN…
|
NVD-CWE-Other
|
CVE-2002-0029
|
2008-09-11 04:11 |
2002-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346244
|
4.6 |
MEDIUM
|
adobe
|
acrobat acrobat_reader
|
The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by…
|
NVD-CWE-Other
|
CVE-2002-0030
|
2008-09-11 04:11 |
2003-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346245
|
7.2 |
HIGH
|
bindview funk_software
|
netrc funk_software_proxy
|
Funk Software Proxy Host 3.x is installed with insecure permissions for the registry and the file system.
|
NVD-CWE-Other
|
CVE-2002-0064
|
2008-09-11 04:11 |
2002-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346246
|
7.2 |
HIGH
|
bindview funk_software
|
netrc funk_software_proxy
|
Funk Software Proxy Host 3.x uses weak encryption for the Proxy Host password, which allows local users to gain privileges by recovering the passwords from the PHOST.INI file or the Windows registry.
|
NVD-CWE-Other
|
CVE-2002-0065
|
2008-09-11 04:11 |
2002-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346247
|
7.5 |
HIGH
|
bindview funk_software
|
netrc funk_software_proxy
|
Funk Software Proxy Host 3.x before 3.09A creates a Named Pipe that does not require authentication and is installed with insecure access control, which allows local and possibly remote users to use …
|
NVD-CWE-Other
|
CVE-2002-0066
|
2008-09-11 04:11 |
2002-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346248
|
7.5 |
HIGH
|
geeklog
|
geeklog
|
Geeklog 1.3 allows remote attackers to hijack user accounts, including the administrator account, by modifying the UID of a user's permanent cookie to the target account.
|
NVD-CWE-Other
|
CVE-2002-0097
|
2008-09-11 04:11 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346249
|
7.5 |
HIGH
|
scott_parish
|
chuid
|
Directory traversal vulnerability in chuid 1.2 and earlier allows remote attackers to change the ownership of files outside of the upload directory via a .. (dot dot) attack.
|
NVD-CWE-Other
|
CVE-2002-0144
|
2008-09-11 04:11 |
2002-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346250
|
7.5 |
HIGH
|
apple
|
quicktime
|
Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrary code via a long pluginspage field.
|
NVD-CWE-Other
|
CVE-2002-0376
|
2008-09-11 04:11 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|