|
352901
|
7.5 |
HIGH
|
van_dyke_technologies
|
securecrt
|
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string.
|
NVD-CWE-Other
|
CVE-2002-1059
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352902
|
5.0 |
MEDIUM
|
d-link
|
dp-303
|
The web server for D-Link DP-300 print server allows remote attackers to cause a denial of service (hang) via a large HTTP POST request.
|
NVD-CWE-Other
|
CVE-2002-1068
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352903
|
5.0 |
MEDIUM
|
d-link
|
di-804
|
The remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP addresses or obtain sensitive information via a direct web req…
|
NVD-CWE-Other
|
CVE-2002-1069
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352904
|
7.5 |
HIGH
|
mozilla netscape opera_software
|
mozilla navigator opera_web_browser
|
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
|
NVD-CWE-Other
|
CVE-2002-1091
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352905
|
2.1 |
LOW
|
amavis
|
virus_scanner
|
securetar, as used in AMaViS shell script 0.2.1 and earlier, allows users to cause a denial of service (CPU consumption) via a malformed TAR file, possibly via an incorrect file size parameter.
|
NVD-CWE-Other
|
CVE-2002-1109
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352906
|
10.0 |
HIGH
|
mantis
|
mantis
|
Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operati…
|
NVD-CWE-Other
|
CVE-2002-1110
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352907
|
7.5 |
HIGH
|
mantis
|
mantis
|
config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_include_page, (2) g_top_include_page, (3) g_css_inclu…
|
NVD-CWE-Other
|
CVE-2002-1114
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352908
|
5.0 |
MEDIUM
|
mantis
|
mantis
|
Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page…
|
NVD-CWE-Other
|
CVE-2002-1115
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352909
|
2.1 |
LOW
|
freebsd
|
freebsd
|
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /de…
|
NVD-CWE-Other
|
CVE-2002-1125
|
2016-10-18 11:23 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352910
|
2.6 |
LOW
|
galeon mozilla
|
galeon_browser mozilla
|
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to…
|
NVD-CWE-Other
|
CVE-2002-1126
|
2016-10-18 11:23 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352911
|
7.5 |
HIGH
|
gfi network_associates roaring_penguin trend_micro
|
mailsecurity webshield_smtp canit mimedefang interscan_viruswall
|
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and …
|
NVD-CWE-Other
|
CVE-2002-1121
|
2016-10-18 11:23 |
2002-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352912
|
7.2 |
HIGH
|
compaq digital
|
tru64 osf_1
|
Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.
|
NVD-CWE-Other
|
CVE-2002-1129
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352913
|
5.0 |
MEDIUM
|
funsoft
|
dinos_webserver
|
Encoded directory traversal vulnerability in Dino's web server 2.1 allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "\" (%5c) charac…
|
NVD-CWE-Other
|
CVE-2002-1133
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352914
|
5.0 |
MEDIUM
|
hp
|
webes_service_tools
|
Unknown vulnerability in Compaq WEBES Service Tools 2.0 through WEBES 4.0 (Service Pack 5) allows local users to read privileged files.
|
NVD-CWE-Other
|
CVE-2002-1134
|
2016-10-18 11:23 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352915
|
7.1 |
HIGH
|
cisco
|
ios
|
Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-0813
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352916
|
7.5 |
HIGH
|
vmware
|
gsx_server
|
Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument.
|
NVD-CWE-Other
|
CVE-2002-0814
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352917
|
7.2 |
HIGH
|
compaq
|
tru64
|
Buffer overflow in su in Tru64 Unix 5.x allows local users to gain root privileges via a long username and argument.
|
NVD-CWE-Other
|
CVE-2002-0816
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352918
|
7.2 |
HIGH
|
william_deich
|
super
|
Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.
|
NVD-CWE-Other
|
CVE-2002-0817
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352919
|
7.5 |
HIGH
|
wwwoffle
|
wwwoffle
|
wwwoffled in World Wide Web Offline Explorer (WWWOFFLE) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative Content-Length value.
|
NVD-CWE-Other
|
CVE-2002-0818
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352920
|
7.2 |
HIGH
|
artsd
|
artsd
|
Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly h…
|
NVD-CWE-Other
|
CVE-2002-0819
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352921
|
7.2 |
HIGH
|
freebsd
|
freebsd
|
FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local u…
|
NVD-CWE-Other
|
CVE-2002-0820
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352922
|
4.6 |
MEDIUM
|
freebsd
|
freebsd
|
Integer overflow in the Berkeley Fast File System (FFS) in FreeBSD 4.6.1 RELEASE-p4 and earlier allows local users to access arbitrary file contents within FFS to gain privileges by creating a file t…
|
NVD-CWE-Other
|
CVE-2002-0829
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352923
|
2.1 |
LOW
|
freebsd
|
freebsd
|
The kqueue mechanism in FreeBSD 4.3 through 4.6 STABLE allows local users to cause a denial of service (kernel panic) via a pipe call in which one end is terminated and an EVFILT_WRITE filter is regi…
|
NVD-CWE-Other
|
CVE-2002-0831
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352924
|
7.5 |
HIGH
|
qualcomm
|
eudora
|
Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part message with a long boundary string.
|
NVD-CWE-Other
|
CVE-2002-0833
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352925
|
7.5 |
HIGH
|
hp mandrakesoft redhat
|
secure_os mandrake_linux linux
|
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involvin…
|
NVD-CWE-Other
|
CVE-2002-0836
|
2016-10-18 11:22 |
2002-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352926
|
7.5 |
HIGH
|
wordtrans
|
wordtrans-web
|
wordtrans 1.1pre8 and earlier in the wordtrans-web package allows remote attackers to (1) execute arbitrary code or (2) conduct cross-site scripting attacks via certain parameters (possibly "dict") t…
|
NVD-CWE-Other
|
CVE-2002-0837
|
2016-10-18 11:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352927
|
4.6 |
MEDIUM
|
ggv ghostview gv
|
ggv ghostview gv
|
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arb…
|
NVD-CWE-Other
|
CVE-2002-0838
|
2016-10-18 11:22 |
2002-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352928
|
7.5 |
HIGH
|
oracle
|
application_server
|
Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code…
|
NVD-CWE-Other
|
CVE-2002-0842
|
2016-10-18 11:22 |
2003-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352929
|
7.5 |
HIGH
|
iplanet
|
iplanet_web_server
|
Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding.
|
NVD-CWE-Other
|
CVE-2002-0845
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352930
|
7.5 |
HIGH
|
macromedia
|
shockwave_flash
|
The decoder for Macromedia Shockwave Flash allows remote attackers to execute arbitrary code via a malformed SWF header that contains more data than the specified length.
|
NVD-CWE-Other
|
CVE-2002-0846
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352931
|
4.6 |
MEDIUM
|
cisco
|
iscsi_driver
|
Linux-iSCSI iSCSI implementation installs the iscsi.conf file with world-readable permissions on some operating systems, including Red Hat Linux Limbo Beta #1, which could allow local users to gain p…
|
NVD-CWE-Other
|
CVE-2002-0849
|
2016-10-18 11:22 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352932
|
7.5 |
HIGH
|
oracle
|
database_server oracle8i
|
Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing…
|
NVD-CWE-Other
|
CVE-2002-0857
|
2016-10-18 11:22 |
2002-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352933
|
7.5 |
HIGH
|
oracle
|
oracle8i oracle9i
|
catsnmp in Oracle 9i and 8i is installed with a dbsnmp user with a default dbsnmp password, which allows attackers to perform restricted database operations and possibly gain other privileges.
|
NVD-CWE-Other
|
CVE-2002-0858
|
2016-10-18 11:22 |
2002-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352934
|
2.1 |
LOW
|
caldera
|
openserver
|
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.
|
NVD-CWE-Other
|
CVE-2002-0887
|
2016-10-18 11:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352935
|
4.6 |
MEDIUM
|
qualcomm
|
qpopper
|
Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a long bulldir argument in the user's .qpopper-options co…
|
NVD-CWE-Other
|
CVE-2002-0889
|
2016-10-18 11:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352936
|
5.0 |
MEDIUM
|
opera_software
|
opera_web_browser
|
Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an input type=file tag whose value contains a newline.
|
NVD-CWE-Other
|
CVE-2002-0898
|
2016-10-18 11:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352937
|
7.5 |
HIGH
|
kismet
|
kismet
|
SayText function in Kismet 2.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters (backtick or pipe) in the essid argument.
|
NVD-CWE-Other
|
CVE-2002-0904
|
2016-10-18 11:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352938
|
7.5 |
HIGH
|
matsushita_research
|
mnews
|
Multiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local users can gain privileges via long command line arguments (2)…
|
NVD-CWE-Other
|
CVE-2002-0909
|
2016-10-18 11:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352939
|
7.5 |
HIGH
|
stephen_hebditch
|
slurp
|
Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response.
|
NVD-CWE-Other
|
CVE-2002-0913
|
2016-10-18 11:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352940
|
7.5 |
HIGH
|
sgi
|
irix
|
xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_…
|
NVD-CWE-Other
|
CVE-2002-0652
|
2016-10-18 11:21 |
2002-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352941
|
2.1 |
LOW
|
dan_mueth
|
scrollkeeper
|
scrollkeeper-get-cl in ScrollKeeper 0.3 to 0.3.11 allows local users to create and overwrite files via a symlink attack on the scrollkeeper-tempfile.x temporary files.
|
NVD-CWE-Other
|
CVE-2002-0662
|
2016-10-18 11:21 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352942
|
7.5 |
HIGH
|
granite_software
|
zmerge
|
The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to…
|
NVD-CWE-Other
|
CVE-2002-0664
|
2016-10-18 11:21 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352943
|
10.0 |
HIGH
|
macromedia
|
jrun
|
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.
|
NVD-CWE-Other
|
CVE-2002-0665
|
2016-10-18 11:21 |
2002-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352944
|
7.5 |
HIGH
|
pacific_software
|
carello
|
Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.
|
NVD-CWE-Other
|
CVE-2002-0683
|
2016-10-18 11:21 |
2002-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352945
|
7.5 |
HIGH
|
gnu isc
|
glibc bind
|
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execu…
|
NVD-CWE-Other
|
CVE-2002-0684
|
2016-10-18 11:21 |
2002-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352946
|
7.5 |
HIGH
|
pgp
|
desktop_security freeware personal_security
|
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows rem…
|
NVD-CWE-Other
|
CVE-2002-0685
|
2016-10-18 11:21 |
2002-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352947
|
7.5 |
HIGH
|
iplanet
|
iplanet_web_server
|
Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parame…
|
NVD-CWE-Other
|
CVE-2002-0686
|
2016-10-18 11:21 |
2002-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352948
|
2.1 |
LOW
|
freebsd openbsd
|
freebsd openbsd
|
ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive …
|
NVD-CWE-Other
|
CVE-2002-0701
|
2016-10-18 11:21 |
2002-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352949
|
10.0 |
HIGH
|
isc
|
dhcpd
|
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to …
|
NVD-CWE-Other
|
CVE-2002-0702
|
2016-10-18 11:21 |
2002-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352950
|
7.5 |
HIGH
|
surfcontrol
|
superscout_web_filter web_filter
|
The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames a…
|
NVD-CWE-Other
|
CVE-2002-0705
|
2016-10-18 11:21 |
2002-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|