|
347651
|
5.1 |
MEDIUM
|
activxperts_software microsoft
|
activwebserver windows_2003_server
|
Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.
|
NVD-CWE-Other
|
CVE-2002-2189
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347652
|
7.5 |
HIGH
|
artscore_studios
|
cutecast_forum
|
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
|
NVD-CWE-Other
|
CVE-2002-2190
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347653
|
5.0 |
MEDIUM
|
lotus
|
domino
|
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non…
|
NVD-CWE-Other
|
CVE-2002-2191
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347654
|
5.0 |
MEDIUM
|
lotus
|
domino
|
This issue is present on Lotus Domino Server with the 'DominoNoBanner' set to a value of '1'.
|
NVD-CWE-Other
|
CVE-2002-2191
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347655
|
4.3 |
MEDIUM
|
perception
|
liteserve
|
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query…
|
NVD-CWE-Other
|
CVE-2002-2192
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347656
|
4.3 |
MEDIUM
|
perception
|
liteserve
|
This vulnerability is limited to server configurations with Wildcard DNS enabled.
|
NVD-CWE-Other
|
CVE-2002-2192
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347657
|
4.3 |
MEDIUM
|
mojo_mail
|
mojo_mail
|
Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter.
|
NVD-CWE-Other
|
CVE-2002-2193
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347658
|
5.0 |
MEDIUM
|
nullsoft
|
winamp
|
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.
|
NVD-CWE-Other
|
CVE-2002-2195
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347659
|
7.5 |
HIGH
|
samba
|
samba
|
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2196
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347660
|
10.0 |
HIGH
|
zmailer
|
zmailer
|
Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing from an IPv6 address, possibly using an address that resolves to a long hostname.
|
NVD-CWE-Other
|
CVE-2002-2198
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347661
|
10.0 |
HIGH
|
webmin
|
webmin
|
The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the printer name.
|
NVD-CWE-Other
|
CVE-2002-2201
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347662
|
3.8 |
LOW
|
microsoft
|
outlook_express
|
Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.
|
NVD-CWE-Other
|
CVE-2002-2202
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347663
|
3.8 |
LOW
|
microsoft
|
outlook_express
|
This vulnerability affects Outlook Express 6.0 on any version of the Windows OS.
|
NVD-CWE-Other
|
CVE-2002-2202
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347664
|
7.5 |
HIGH
|
redhat
|
redhat_package_manager
|
The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicio…
|
NVD-CWE-Other
|
CVE-2002-2204
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347665
|
7.5 |
HIGH
|
redhat
|
redhat_package_manager
|
A large degree of social engineering and user interaction is neccessary to exploit this vulnerbility.
|
NVD-CWE-Other
|
CVE-2002-2204
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347666
|
5.0 |
MEDIUM
|
webresolve
|
webresolve
|
Buffer overflow in Webresolve 0.1.0 and earlier allows remote attackers to execute arbitrary code by connecting to the server from an IP address that resolves to a long hostname.
|
NVD-CWE-Other
|
CVE-2002-2205
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347667
|
7.8 |
HIGH
|
symantec
|
norton_antivirus
|
The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries.
|
NVD-CWE-Other
|
CVE-2002-2206
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347668
|
10.0 |
HIGH
|
eric_rescorla
|
ssldump
|
Buffer overflow in ssldump 0.9b2 and earlier, when running in decryption mode, allows remote attackers to execute arbitrary code via a long RSA PreMasterSecret.
|
NVD-CWE-Other
|
CVE-2002-2207
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347669
|
10.0 |
HIGH
|
pablo_software_solutions
|
baby_ftp_server
|
Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2002-2209
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347670
|
6.2 |
MEDIUM
|
openoffice
|
openoffice
|
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file.
|
NVD-CWE-Other
|
CVE-2002-2210
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347671
|
5.0 |
MEDIUM
|
isc fujitsu
|
bind uxp_v
|
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that …
|
NVD-CWE-Other
|
CVE-2002-2212
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347672
|
5.0 |
MEDIUM
|
infoblox isc
|
dns_one bind
|
The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack th…
|
NVD-CWE-Other
|
CVE-2002-2213
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347673
|
5.0 |
MEDIUM
|
php
|
php
|
The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header.
|
NVD-CWE-Other
|
CVE-2002-2214
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347674
|
5.0 |
MEDIUM
|
php
|
php
|
The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which trigger…
|
NVD-CWE-Other
|
CVE-2002-2215
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347675
|
5.0 |
MEDIUM
|
php
|
php
|
This vulnerability is addressed in the following product release:
PHP, PHP, 4.3.0
|
NVD-CWE-Other
|
CVE-2002-2215
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347676
|
5.0 |
MEDIUM
|
soft3304
|
04webserver
|
Soft3304 04WebServer before 1.20 does not properly process URL strings, which allows remote attackers to obtain unspecified sensitive information.
|
NVD-CWE-Other
|
CVE-2002-2216
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347677
|
10.0 |
HIGH
|
sips
|
sips
|
CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impact, possibly gainin…
|
NVD-CWE-Other
|
CVE-2002-2218
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347678
|
6.2 |
MEDIUM
|
chetcpasswd
|
chetcpasswd
|
Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2002-2220
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347679
|
6.2 |
MEDIUM
|
chetcpasswd
|
chetcpasswd
|
Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issu…
|
NVD-CWE-Other
|
CVE-2002-2221
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347680
|
5.1 |
MEDIUM
|
safenet
|
softremote_vpn_client
|
SafeNet VPN client allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly involving buffer overflo…
|
NVD-CWE-Other
|
CVE-2002-2225
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347681
|
6.4 |
MEDIUM
|
mailscanner
|
mailscanner
|
MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate c…
|
CWE-20
Improper Input Validation
|
CVE-2002-2228
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347682
|
5.0 |
MEDIUM
|
sapio_design_ltd
|
webreflex
|
Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request.
|
CWE-22
Path Traversal
|
CVE-2002-2229
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347683
|
8.5 |
HIGH
|
mollensoft_software
|
enceladus_server_suite
|
Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2232
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347684
|
4.3 |
MEDIUM
|
netscreen
|
screenos
|
NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests.
|
CWE-16
Configuration
|
CVE-2002-2234
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347685
|
5.0 |
MEDIUM
|
jelsoft
|
vbulletin
|
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which fac…
|
CWE-189
Numeric Errors
|
CVE-2002-2235
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347686
|
10.0 |
HIGH
|
apt-www-proxy
|
apt-www-proxy
|
Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2002-2236
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347687
|
5.0 |
MEDIUM
|
netbsd
|
ftpd
|
ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls an…
|
CWE-189
Numeric Errors
|
CVE-2002-2245
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347688
|
10.0 |
HIGH
|
hp
|
secure_web_server_for_tru64
|
Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might…
|
NVD-CWE-noinfo
|
CVE-2002-2264
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347689
|
10.0 |
HIGH
|
hp
|
secure_web_server_for_tru64
|
More Information: http://www.securityfocus.com/bid/6175/info
|
NVD-CWE-noinfo
|
CVE-2002-2264
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347690
|
5.0 |
MEDIUM
|
pyramid
|
benhur_software_update
|
The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20.
|
NVD-CWE-Other
|
CVE-2002-2307
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347691
|
5.0 |
MEDIUM
|
netscape
|
communicator
|
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL ta…
|
NVD-CWE-Other
|
CVE-2002-2308
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347692
|
7.8 |
HIGH
|
php
|
php
|
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
|
CWE-399
Resource Management Errors
|
CVE-2002-2309
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347693
|
5.0 |
MEDIUM
|
kryptronic
|
clickcartpro
|
ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and pa…
|
CWE-255
Credentials Management
|
CVE-2002-2310
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347694
|
5.8 |
MEDIUM
|
opera_software
|
opera
|
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a web…
|
NVD-CWE-Other
|
CVE-2002-2312
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347695
|
8.8 |
HIGH
|
qualcomm
|
eudora
|
Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedd…
|
NVD-CWE-Other
|
CVE-2002-2313
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347696
|
5.0 |
MEDIUM
|
mozilla
|
mozilla
|
Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.
|
CWE-20
Improper Input Validation
|
CVE-2002-2314
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347697
|
7.8 |
HIGH
|
cisco
|
ios
|
Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the rou…
|
NVD-CWE-Other
|
CVE-2002-2315
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347698
|
5.0 |
MEDIUM
|
cisco
|
catos
|
Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switc…
|
NVD-CWE-Other
|
CVE-2002-2316
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347699
|
7.8 |
HIGH
|
symantec
|
velociraptor
|
Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumption) via an unknown method.
|
NVD-CWE-noinfo CWE-200
Information Exposure
|
CVE-2002-2317
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347700
|
4.3 |
MEDIUM
|
blueface
|
falcon_web_server
|
Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 erro…
|
CWE-79
Cross-site Scripting
|
CVE-2002-2318
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|