|
351751
|
7.5 |
HIGH
|
phprojekt
|
phprojekt
|
PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with "sms" in the URL, w…
|
NVD-CWE-Other
|
CVE-2002-1757
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351752
|
5.0 |
MEDIUM
|
phprojekt
|
phprojekt
|
PHProjekt 2.0 through 3.1 allows remote attackers to view or modify data via requests to certain scripts that do not verify if the user is logged in.
|
NVD-CWE-Other
|
CVE-2002-1758
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351753
|
7.5 |
HIGH
|
phprojekt
|
phprojekt
|
Multiple SQL injection vulnerabilities in PHProjekt 2.0 through 3.1 allow remote attackers to execute arbitrary SQL commands via the unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2002-1760
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351754
|
5.0 |
MEDIUM
|
microsoft
|
baseline_security_analyzer
|
Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain s…
|
NVD-CWE-Other
|
CVE-2002-1762
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351755
|
2.1 |
LOW
|
adobe
|
acrobat_reader
|
acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2002-1764
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351756
|
5.0 |
MEDIUM
|
ximian
|
evolution
|
Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (memory consumption and crash) via an email with a malformed MIME header.
|
NVD-CWE-Other
|
CVE-2002-1765
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351757
|
4.6 |
MEDIUM
|
netscape
|
communicator
|
Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.
|
NVD-CWE-Other
|
CVE-2002-1766
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351758
|
7.2 |
HIGH
|
oracle
|
database_server
|
Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user via a long command line argument.
|
NVD-CWE-Other
|
CVE-2002-1767
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351759
|
5.0 |
MEDIUM
|
cisco
|
ios
|
Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly sized UDP packets to the Hot Standby Routing Protoco…
|
NVD-CWE-Other
|
CVE-2002-1768
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351760
|
5.0 |
MEDIUM
|
qualcomm
|
eudora
|
Qualcomm Eudora 5.1 allows remote attackers to execute arbitrary code via an HTML e-mail message that uses a file:// URL in a t:video tag to reference an attached Windows Media Player file containing…
|
NVD-CWE-Other
|
CVE-2002-1770
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351761
|
5.0 |
MEDIUM
|
matt_wright
|
formmail
|
Matt Wright FormMail 1.9 and earlier allows remote attackers to send spam or anonymous e-mail by injecting a newline character followed by CC:, BCC:, or additional TO: fields in the email and realnam…
|
NVD-CWE-Other
|
CVE-2002-1771
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351762
|
4.6 |
MEDIUM
|
novell
|
netware
|
Novell Netware 5.0 through 5.1 may allow local users to gain "Domain Admin" rights by logging into a Novell Directory Services (NDS) account, and executing "net use" on an NDS_ADM account that is not…
|
NVD-CWE-Other
|
CVE-2002-1772
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351763
|
7.5 |
HIGH
|
mirabilis
|
icq_for_macos_x
|
Buffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request.
|
NVD-CWE-Other
|
CVE-2002-1773
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351764
|
7.5 |
HIGH
|
symantec
|
norton_personal_firewall
|
Symantec Norton Personal Firewall 2002 allows remote attackers to bypass the portscan protection by using a (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH scan.
|
NVD-CWE-Other
|
CVE-2002-1778
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351765
|
5.0 |
MEDIUM
|
alcatech_gmbh
|
bpm_studio_pro
|
BPM Studio Pro 4.2 by ALCATech GmbH includes a webserver that allows a remote attacker to cause a denial of service (crash) by sending a URL request for a MS-DOS device such as con. NOTE: it has bee…
|
NVD-CWE-Other
|
CVE-2002-1780
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351766
|
7.5 |
HIGH
|
delegate
|
delegate
|
Multiple buffer overflows in DeleGate 7.7.0 through 7.8.1 allow remote attackers to execute arbitrary code, as demonstrated using a long USER command to the POP proxy.
|
NVD-CWE-Other
|
CVE-2002-1781
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351767
|
2.1 |
LOW
|
university_of_washington
|
uw-imap
|
The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP account to read arbitrar…
|
NVD-CWE-Other
|
CVE-2002-1782
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351768
|
5.0 |
MEDIUM
|
php
|
php
|
CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected…
|
NVD-CWE-Other
|
CVE-2002-1783
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351769
|
4.3 |
MEDIUM
|
openbb
|
openbb
|
Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror a…
|
NVD-CWE-Other
|
CVE-2002-1829
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351770
|
10.0 |
HIGH
|
microsoft
|
data_access_components
|
Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details …
|
NVD-CWE-Other
|
CVE-2002-1918
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351771
|
2.1 |
LOW
|
aquonics_scripting
|
aquonics_file_manager
|
Aquonics File Manager 1.5 allows users with edit privileges to modify user accounts by editing the userlist.cgi file.
|
NVD-CWE-Other
|
CVE-2002-1927
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351772
|
2.1 |
LOW
|
qnx
|
rtos
|
The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.
|
NVD-CWE-Other
|
CVE-2002-1983
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351773
|
7.5 |
HIGH
|
zonelabs
|
zonealarm
|
ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.
|
NVD-CWE-Other
|
CVE-2002-1997
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351774
|
6.4 |
MEDIUM
|
xqus
|
x-stat
|
x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to (1) execute PHP commands such as phpinfo or (2) obtain the full path of the web server via an invalid action parameter, which lea…
|
NVD-CWE-Other
|
CVE-2002-2045
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351775
|
4.3 |
MEDIUM
|
squirrelmail
|
squirrelmail
|
Multiple cross-site scripting (XSS) vulnerabilities in magicHTML of SquirrelMail before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via (1) "<<script" in unspecified input fie…
|
NVD-CWE-Other
|
CVE-2002-2086
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351776
|
5.0 |
MEDIUM
|
gianni_tedesco
|
fwmon
|
Fwmon before 1.0.10 allows remote attackers to cause a denial of service (crash) by causing the kernel to return a large packet.
|
NVD-CWE-Other
|
CVE-2002-2111
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351777
|
7.5 |
HIGH
|
netjuke
|
netjuke
|
Artekopia Netjuke before 1.0 b7 allows remote attackers to execute arbitrary code on the web server, possibly via the section parameter, which is passed to an eval call.
|
NVD-CWE-Other
|
CVE-2002-2114
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351778
|
7.5 |
HIGH
|
gallery_project
|
gallery
|
PHP remote file inclusion vulnerability in publish_xp_docs.php for Gallery 1.3.2 allows remote attackers to inject arbitrary PHP code by specifying a URL to an init.php file in the GALLERY_BASEDIR pa…
|
NVD-CWE-Other
|
CVE-2002-2123
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351779
|
5.0 |
MEDIUM
|
nylon
|
nylon
|
The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closin…
|
NVD-CWE-Other
|
CVE-2002-2124
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351780
|
2.1 |
LOW
|
pedestal_software
|
integrity_protection_driver
|
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device …
|
NVD-CWE-Other
|
CVE-2002-2127
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351781
|
4.3 |
MEDIUM
|
w-agora
|
w-agora
|
Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is ech…
|
NVD-CWE-Other
|
CVE-2002-2129
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351782
|
7.5 |
HIGH
|
oracle
|
application_server
|
Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2002-2153
|
2017-07-11 10:29 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351783
|
7.5 |
HIGH
|
ftp_desktop
|
ftp_desktop
|
Multiple heap-based buffer overflows in FTP Desktop client 3.5, and possibly earlier versions, allow remote malicious servers to execute arbitrary code via (1) a long FTP banner, (2) a long response …
|
NVD-CWE-Other
|
CVE-2003-0766
|
2017-04-29 10:59 |
2003-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351784
|
4.6 |
MEDIUM
|
nosque
|
msgcore
|
Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to…
|
NVD-CWE-Other
|
CVE-1999-1353
|
2017-04-29 10:59 |
1999-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351785
|
7.2 |
HIGH
|
ibm
|
aix
|
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.
|
NVD-CWE-Other
|
CVE-2001-1329
|
2017-04-29 10:59 |
2001-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351786
|
7.2 |
HIGH
|
linux
|
linux_kernel
|
The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses…
|
NVD-CWE-Other
|
CVE-2005-1589
|
2017-02-19 14:08 |
2005-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351787
|
2.6 |
LOW
|
linux
|
linux_kernel
|
Race condition in the sysfs_read_file and sysfs_write_file functions in Linux kernel before 2.6.10 allows local users to read kernel memory and cause a denial of service (crash) via large offsets in …
|
NVD-CWE-Other
|
CVE-2004-2302
|
2017-02-19 14:07 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351788
|
5.0 |
MEDIUM
|
cabletron
|
smartswitch_router_8000_firmware
|
Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.
|
NVD-CWE-Other
|
CVE-1999-1548
|
2017-02-16 11:59 |
1999-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351789
|
5.0 |
MEDIUM
|
microsoft
|
windows_2003_server windows_xp
|
The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the S…
|
NVD-CWE-Other
|
CVE-2005-1649
|
2017-01-20 11:59 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351790
|
5.0 |
MEDIUM
|
sun
|
sdk
|
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in f…
|
NVD-CWE-Other
|
CVE-2005-1080
|
2017-01-3 11:59 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351791
|
5.0 |
MEDIUM
|
unix
|
unix
|
Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.
|
NVD-CWE-Other
|
CVE-1999-0377
|
2016-12-28 11:59 |
1999-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351792
|
2.1 |
LOW
|
gnu
|
mailman
|
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
|
NVD-CWE-Other
|
CVE-2002-0389
|
2016-12-28 11:59 |
2002-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351793
|
7.8 |
HIGH
|
intel
|
graphics_accelerator_driver
|
ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, a…
|
CWE-399
Resource Management Errors
|
CVE-2006-0081
|
2016-12-20 11:59 |
2006-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351794
|
10.0 |
HIGH
|
suse
|
suse_linux
|
The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.
|
NVD-CWE-Other
|
CVE-2005-2023
|
2016-12-20 11:59 |
2005-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351795
|
7.5 |
HIGH
|
protector_system
|
protector_system
|
blocker.php in Protector System 1.15b1 allows remote attackers to bypass SQL injection protection and execute limited SQL commands via URL-encoded "'" characters ("%27").
|
NVD-CWE-Other
|
CVE-2004-1961
|
2016-12-20 11:59 |
2004-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351796
|
5.0 |
MEDIUM
|
pi3
|
pi3web
|
Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (c…
|
NVD-CWE-Other
|
CVE-2003-1032
|
2016-12-20 11:59 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351797
|
2.1 |
LOW
|
padl_software
|
migrationtools
|
PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly created by (1) mig…
|
NVD-CWE-Other
|
CVE-2006-0512
|
2016-12-8 12:00 |
2006-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351798
|
5.0 |
MEDIUM
|
openbsd
|
openssh
|
OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address is not provided, which may cause OpenSSH to enable the GatewayPorts fu…
|
NVD-CWE-Other
|
CVE-2005-2797
|
2016-12-8 12:00 |
2005-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351799
|
10.0 |
HIGH
|
carnegie_mellon_university openpkg conectiva redhat trustix ubuntu
|
cyrus_imap_server openpkg linux fedora_core secure_linux ubuntu_linux
|
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p"…
|
NVD-CWE-Other
|
CVE-2004-1013
|
2016-12-8 11:59 |
2005-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
351800
|
3.6 |
LOW
|
mantis
|
mantis
|
Mantis 0.17.5 and earlier stores its database password in cleartext in a world-readable configuration file, which allows local users to perform unauthorized database operations.
|
NVD-CWE-Other
|
CVE-2003-0499
|
2016-12-8 11:59 |
2003-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|