270101
|
5.0 |
MEDIUM
|
microsoft
|
outlook_express
|
Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.
|
NVD-CWE-Other
|
CVE-2002-2164
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270102
|
2.1 |
LOW
|
imho
|
imho_webmail
|
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.
|
NVD-CWE-Other
|
CVE-2002-2165
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270103
|
4.3 |
MEDIUM
|
e-zone_media_inc.
|
fusetalk
|
Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script.
|
NVD-CWE-Other
|
CVE-2002-2166
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270104
|
5.0 |
MEDIUM
|
thorsten_korner
|
123tkshop
|
Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null…
|
NVD-CWE-Other
|
CVE-2002-2167
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270105
|
7.5 |
HIGH
|
thorsten_korner
|
123tkshop
|
SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL queries via various programs including function_describe_item1.inc.php.
|
NVD-CWE-Other
|
CVE-2002-2168
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270106
|
5.0 |
MEDIUM
|
aol
|
instant_messenger
|
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a use…
|
NVD-CWE-Other
|
CVE-2002-2169
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270107
|
7.5 |
HIGH
|
working_resources_inc.
|
badblue
|
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, whic…
|
NVD-CWE-Other
|
CVE-2002-2170
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270108
|
2.1 |
LOW
|
shana
|
informed_designer informed_filler
|
Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2002-2172
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270109
|
7.5 |
HIGH
|
cerulean_studios
|
trillian
|
Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a long DCC Chat message.
|
NVD-CWE-Other
|
CVE-2002-2173
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270110
|
5.0 |
MEDIUM
|
software602
|
602pro_lan_suite
|
The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (memory consumption) v…
|
NVD-CWE-Other
|
CVE-2002-2174
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270111
|
10.0 |
HIGH
|
phpbb_group
|
phpbb
|
SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.
|
NVD-CWE-Other
|
CVE-2002-2176
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270112
|
4.3 |
MEDIUM
|
phpwebsite
|
phpwebsite
|
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG …
|
NVD-CWE-Other
|
CVE-2002-2178
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270113
|
4.3 |
MEDIUM
|
phpwebsite
|
phpwebsite
|
This vulnerability affects phpWebsite version 0.8.3, and may affect all other versions of phpWebsite.
|
NVD-CWE-Other
|
CVE-2002-2178
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270114
|
7.8 |
HIGH
|
unisys
|
clearpath_mcp
|
The dynamic initialization feature of the ClearPath MCP environment allows remote attackers to cause a denial of service (crash) via a TCP port scan using a tool such as nmap.
|
NVD-CWE-Other
|
CVE-2002-2179
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270115
|
7.8 |
HIGH
|
unisys
|
clearpath_mcp
|
This vulnarability may affect all versions of Unisys, ClearPath MCP.
|
NVD-CWE-Other
|
CVE-2002-2179
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270116
|
6.8 |
MEDIUM
|
openbsd
|
openbsd
|
The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via a…
|
NVD-CWE-Other
|
CVE-2002-2180
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270117
|
5.0 |
MEDIUM
|
sonicwall
|
content_filtering
|
SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.
|
NVD-CWE-Other
|
CVE-2002-2181
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270118
|
6.4 |
MEDIUM
|
seunghyun_seo
|
msn666
|
Buffer overflow in Seunghyun Seo's MSN666 MSN Sniffer 1.0 and 1.0.1 allows remote attackers to execute arbitrary code via a long MSN packet.
|
NVD-CWE-Other
|
CVE-2002-2182
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270119
|
7.5 |
HIGH
|
phpshare
|
phpshare
|
phpShare.php in phpShare before 0.6 beta 3 allows remote attackers to include and execute arbitrary PHP scripts from remote servers.
|
NVD-CWE-Other
|
CVE-2002-2183
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270120
|
5.0 |
MEDIUM
|
digi-net_technologies
|
digichat
|
Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet.
|
NVD-CWE-Other
|
CVE-2002-2184
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270121
|
5.0 |
MEDIUM
|
macromedia
|
jrun
|
Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL.
|
NVD-CWE-Other
|
CVE-2002-2186
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270122
|
5.0 |
MEDIUM
|
macromedia
|
jrun
|
Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.
|
NVD-CWE-Other
|
CVE-2002-2187
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270123
|
4.9 |
MEDIUM
|
openbsd
|
openbsd
|
OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error.
|
NVD-CWE-Other
|
CVE-2002-2188
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270124
|
5.1 |
MEDIUM
|
activxperts_software microsoft
|
activwebserver windows_2003_server
|
Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.
|
NVD-CWE-Other
|
CVE-2002-2189
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270125
|
7.5 |
HIGH
|
artscore_studios
|
cutecast_forum
|
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
|
NVD-CWE-Other
|
CVE-2002-2190
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270126
|
5.0 |
MEDIUM
|
lotus
|
domino
|
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non…
|
NVD-CWE-Other
|
CVE-2002-2191
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270127
|
5.0 |
MEDIUM
|
lotus
|
domino
|
This issue is present on Lotus Domino Server with the 'DominoNoBanner' set to a value of '1'.
|
NVD-CWE-Other
|
CVE-2002-2191
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270128
|
4.3 |
MEDIUM
|
perception
|
liteserve
|
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query…
|
NVD-CWE-Other
|
CVE-2002-2192
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270129
|
4.3 |
MEDIUM
|
perception
|
liteserve
|
This vulnerability is limited to server configurations with Wildcard DNS enabled.
|
NVD-CWE-Other
|
CVE-2002-2192
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270130
|
4.3 |
MEDIUM
|
mojo_mail
|
mojo_mail
|
Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter.
|
NVD-CWE-Other
|
CVE-2002-2193
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270131
|
5.0 |
MEDIUM
|
nullsoft
|
winamp
|
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.
|
NVD-CWE-Other
|
CVE-2002-2195
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270132
|
7.5 |
HIGH
|
samba
|
samba
|
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
|
CWE-119
バッファエラー
|
CVE-2002-2196
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270133
|
10.0 |
HIGH
|
zmailer
|
zmailer
|
Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing from an IPv6 address, possibly using an address that resolves to a long hostname.
|
NVD-CWE-Other
|
CVE-2002-2198
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270134
|
10.0 |
HIGH
|
webmin
|
webmin
|
The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the printer name.
|
NVD-CWE-Other
|
CVE-2002-2201
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270135
|
3.8 |
LOW
|
microsoft
|
outlook_express
|
Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.
|
NVD-CWE-Other
|
CVE-2002-2202
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270136
|
3.8 |
LOW
|
microsoft
|
outlook_express
|
This vulnerability affects Outlook Express 6.0 on any version of the Windows OS.
|
NVD-CWE-Other
|
CVE-2002-2202
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270137
|
7.5 |
HIGH
|
redhat
|
redhat_package_manager
|
The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicio…
|
NVD-CWE-Other
|
CVE-2002-2204
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270138
|
7.5 |
HIGH
|
redhat
|
redhat_package_manager
|
A large degree of social engineering and user interaction is neccessary to exploit this vulnerbility.
|
NVD-CWE-Other
|
CVE-2002-2204
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270139
|
5.0 |
MEDIUM
|
webresolve
|
webresolve
|
Buffer overflow in Webresolve 0.1.0 and earlier allows remote attackers to execute arbitrary code by connecting to the server from an IP address that resolves to a long hostname.
|
NVD-CWE-Other
|
CVE-2002-2205
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270140
|
7.8 |
HIGH
|
symantec
|
norton_antivirus
|
The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries.
|
NVD-CWE-Other
|
CVE-2002-2206
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270141
|
10.0 |
HIGH
|
eric_rescorla
|
ssldump
|
Buffer overflow in ssldump 0.9b2 and earlier, when running in decryption mode, allows remote attackers to execute arbitrary code via a long RSA PreMasterSecret.
|
NVD-CWE-Other
|
CVE-2002-2207
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270142
|
10.0 |
HIGH
|
pablo_software_solutions
|
baby_ftp_server
|
Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2002-2209
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270143
|
6.2 |
MEDIUM
|
openoffice
|
openoffice
|
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file.
|
NVD-CWE-Other
|
CVE-2002-2210
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270144
|
5.0 |
MEDIUM
|
isc fujitsu
|
bind uxp_v
|
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that …
|
NVD-CWE-Other
|
CVE-2002-2212
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270145
|
5.0 |
MEDIUM
|
infoblox isc
|
dns_one bind
|
The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack th…
|
NVD-CWE-Other
|
CVE-2002-2213
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270146
|
5.0 |
MEDIUM
|
php
|
php
|
The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header.
|
NVD-CWE-Other
|
CVE-2002-2214
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270147
|
5.0 |
MEDIUM
|
php
|
php
|
The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which trigger…
|
NVD-CWE-Other
|
CVE-2002-2215
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270148
|
5.0 |
MEDIUM
|
php
|
php
|
This vulnerability is addressed in the following product release:
PHP, PHP, 4.3.0
|
NVD-CWE-Other
|
CVE-2002-2215
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270149
|
5.0 |
MEDIUM
|
soft3304
|
04webserver
|
Soft3304 04WebServer before 1.20 does not properly process URL strings, which allows remote attackers to obtain unspecified sensitive information.
|
NVD-CWE-Other
|
CVE-2002-2216
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270150
|
10.0 |
HIGH
|
sips
|
sips
|
CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impact, possibly gainin…
|
NVD-CWE-Other
|
CVE-2002-2218
|
2008-09-6 05:32 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|