|
347451
|
7.1 |
HIGH
|
netgear
|
fm114p
|
Netgear FM114P firmware 1.3 wireless firewall, when configured to backup configuration information, stores DDNS (DynDNS) user name and password, MAC address filtering table and possibly other informa…
|
CWE-255
Credentials Management
|
CVE-2002-2355
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347452
|
6.4 |
MEDIUM
|
hamweather
|
hamweather
|
HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2356
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347453
|
5.0 |
MEDIUM
|
mailenable
|
mailenable
|
MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string, possibly due to a buffer overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2357
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347454
|
4.3 |
MEDIUM
|
opera_software
|
opera_web_browser
|
Cross-site scripting (XSS) vulnerability in the FTP view feature in Opera 6.0 and 6.01 through 6.04 allows remote attackers to inject arbitrary web script or HTML via the title tag of an FTP URL.
|
CWE-79
Cross-site Scripting
|
CVE-2002-2358
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347455
|
4.3 |
MEDIUM
|
mozilla
|
mozilla
|
Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.
|
CWE-79
Cross-site Scripting
|
CVE-2002-2359
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347456
|
9.3 |
HIGH
|
webmin
|
webmin
|
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_for…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2360
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347457
|
5.8 |
MEDIUM
|
yahoo
|
messenger
|
The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2361
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347458
|
4.3 |
MEDIUM
|
sourceforge
|
mymarket
|
Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2002-2362
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347459
|
7.2 |
HIGH
|
hp
|
hp-ux
|
VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2363
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347460
|
4.3 |
MEDIUM
|
sourceforge
|
php_ticket
|
Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.
|
CWE-79
Cross-site Scripting
|
CVE-2002-2364
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347461
|
10.0 |
HIGH
|
springer_verlag_berlin_heidelberg
|
simple_wais
|
Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.
|
CWE-20
Improper Input Validation
|
CVE-2002-2365
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347462
|
6.8 |
MEDIUM
|
cerulean_studios
|
trillian
|
Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a skin with a long colors fil…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2366
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347463
|
7.8 |
HIGH
|
socks5
|
socks5
|
Off-by-one buffer overflow in NEC SOCKS5 1.0 r11 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hostname.
|
CWE-189 CWE-119
Numeric Errors Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2367
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347464
|
10.0 |
HIGH
|
nec
|
socks_5
|
Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long username to (1) the GetString function i…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2368
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347465
|
5.0 |
MEDIUM
|
perception
|
liteserve
|
Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.
|
CWE-200
Information Exposure
|
CVE-2002-2369
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347466
|
5.0 |
MEDIUM
|
sws
|
sws_simple_web_server
|
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.
|
NVD-CWE-Other
|
CVE-2002-2370
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347467
|
7.8 |
HIGH
|
linksys
|
wet11
|
Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header.
|
CWE-20
Improper Input Validation
|
CVE-2002-2371
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347468
|
5.0 |
MEDIUM
|
ibm
|
infoprint_21
|
The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2372
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347469
|
7.5 |
HIGH
|
apple
|
tcp_ip_configuration_utility
|
The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access.
|
CWE-16
Configuration
|
CVE-2002-2373
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347470
|
10.0 |
HIGH
|
sun
|
patchpro
|
Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."
|
CWE-59 NVD-CWE-noinfo CWE-362
Link Following Race Condition
|
CVE-2002-2374
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347471
|
5.0 |
MEDIUM
|
stalker
|
communigate_pro
|
Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (d…
|
CWE-22
Path Traversal
|
CVE-2002-2375
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347472
|
4.3 |
MEDIUM
|
leung
|
e-guest
|
Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homep…
|
CWE-79
Cross-site Scripting
|
CVE-2002-2376
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347473
|
4.3 |
MEDIUM
|
sephiroth32
|
zap_book
|
Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.
|
CWE-79
Cross-site Scripting
|
CVE-2002-2377
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347474
|
4.3 |
MEDIUM
|
nakata
|
an_httpd
|
Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting erro…
|
CWE-79
Cross-site Scripting
|
CVE-2002-2378
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347475
|
6.4 |
MEDIUM
|
microsoft
|
network_firmware
|
NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic.
|
CWE-200
Information Exposure
|
CVE-2002-2380
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347476
|
7.5 |
HIGH
|
ka-shu_wong
|
gtetrinet
|
Multiple buffer overflows in (1) tetrinet_inmessage, (2) speclist_add and (3) config-getthemeinfo of GTetrinet 0.4.3 and earlier allow remote attackers to casue a denial of service and possibly execu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2381
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347477
|
7.2 |
HIGH
|
cvsup
|
cvsup
|
cvsupd.sh in CVSup 1.2 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on /var/tmp/cvsupd.out.
|
CWE-59
Link Following
|
CVE-2002-2382
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347478
|
3.6 |
LOW
|
hotfoon_corporation
|
hotfoon
|
hotfoon4.exe in Hotfoon 4.00 stores user names and passwords in cleartext in the hotfoon2 registry key, which allows local users to gain access to user accounts and steal phone service.
|
CWE-255
Credentials Management
|
CVE-2002-2384
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347479
|
7.5 |
HIGH
|
hotfoon_corporation
|
hotfoon
|
Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL containing a long voice phone number.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2385
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347480
|
4.3 |
MEDIUM
|
xoops
|
xoops
|
Cross-site scripting (XSS) vulnerability in the Quizz module for XOOPS 1.0, when allowing on-line question development, allows remote attackers to inject arbitrary web script or HTML via a javascript…
|
CWE-79
Cross-site Scripting
|
CVE-2002-2386
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347481
|
5.0 |
MEDIUM
|
mollensoft_software
|
hyperion_ftp_server
|
Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.
|
CWE-22
Path Traversal
|
CVE-2002-2387
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347482
|
5.0 |
MEDIUM
|
inweb
|
mail_server
|
Buffer overflow in INweb POP3 mail server 2.01 allows remote attackers to cause a denial of service (crash) via a long HELO command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2388
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347483
|
5.0 |
MEDIUM
|
fastlink_software
|
the_server
|
TheServer 1.74 web server stores server.ini under the web document root with insufficient access control, which allows remote attackers to obtain cleartext passwords and gain access to server log fil…
|
CWE-255
Credentials Management
|
CVE-2002-2389
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347484
|
10.0 |
HIGH
|
cerulean_studios
|
trillian trillian_pro
|
Buffer overflow in the IDENT daemon (identd) in Trillian 0.6351, 0.725, 0.73, 0.74 and 1.0 pro allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a l…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2390
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347485
|
7.5 |
HIGH
|
webchat.org xoops
|
webchat xoops
|
SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.
|
CWE-89
SQL Injection
|
CVE-2002-2391
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347486
|
6.4 |
MEDIUM
|
nullsoft
|
winamp
|
Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedde…
|
NVD-CWE-Other
|
CVE-2002-2392
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347487
|
5.0 |
MEDIUM
|
trend_micro
|
interscan_viruswall
|
InterScan VirusWall 3.6 for Linux and 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 chunked transfer encoding.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2394
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347488
|
5.0 |
MEDIUM
|
trend_micro
|
interscan_viruswall
|
InterScan VirusWall 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 gzip content encoding.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2395
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347489
|
7.2 |
HIGH
|
remi_lefebvre
|
advanced_tftp
|
Buffer overflow in Advanced TFTP (atftp) 0.5 and 0.6, if installed setuid or setgid, may allow local users to execute arbitrary code via a long argument to the -g option.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2396
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347490
|
10.0 |
HIGH
|
symantec
|
sygate_personal_firewall
|
Sygate personal firewall 5.0 could allow remote attackers to bypass firewall filters via spoofed (1) source IP address of 127.0.0.1 or (2) network address of 127.0.0.0.
|
CWE-287
Improper Authentication
|
CVE-2002-2397
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347491
|
5.0 |
MEDIUM
|
app
|
apboard
|
The new thread posting page in APBoard 2.02 and 2.03 allows remote attackers to post messages to protected forums by modifying the insertinto parameter.
|
NVD-CWE-Other
|
CVE-2002-2398
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347492
|
6.4 |
MEDIUM
|
cascadesoft
|
w3mail
|
Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
CWE-22
Path Traversal
|
CVE-2002-2399
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347493
|
5.0 |
MEDIUM
|
key_focus
|
kf_web_server
|
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequen…
|
CWE-22
Path Traversal
|
CVE-2002-2403
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347494
|
4.9 |
MEDIUM
|
checkpoint
|
firewall-1
|
Check Point FireWall-1 4.1 and Next Generation (NG), with UserAuth configured to proxy HTTP traffic only, allows remote attackers to pass unauthorized HTTPS, FTP and possibly other traffic through th…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2405
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347495
|
5.0 |
MEDIUM
|
perception
|
liteserve
|
Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request.
|
CWE-20
Improper Input Validation
|
CVE-2002-2406
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347496
|
6.9 |
MEDIUM
|
qnx
|
rtos
|
Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) ph…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2002-2407
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347497
|
7.5 |
HIGH
|
gordano
|
ntmail
|
Gordano Messaging Server (GMS) Mail 8 (a.k.a. NTMail) only filters email messages for the first recipient, which allows remote attackers to bypass JUCE filters by sending a message to more than one u…
|
NVD-CWE-Other
|
CVE-2002-2408
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347498
|
3.5 |
LOW
|
qnx
|
neutrino_rtos photon_microgui
|
Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose name …
|
CWE-200
Information Exposure
|
CVE-2002-2409
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347499
|
5.0 |
MEDIUM
|
open_webmail
|
open_webmail
|
openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify v…
|
CWE-200
Information Exposure
|
CVE-2002-2410
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347500
|
2.1 |
LOW
|
nullsoft
|
winamp
|
Winamp 2.80 stores authentication credentials in plaintext in the (1) [HTTP-AUTH] and (2) [winamp] sections in winamp.ini, which allows local users to gain access to other accounts.
|
CWE-255
Credentials Management
|
CVE-2002-2412
|
2008-09-6 05:33 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|