270351
|
10.0 |
HIGH
|
ibm
|
aix
|
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
|
NVD-CWE-Other
|
CVE-2002-1468
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270352
|
7.5 |
HIGH
|
scponly
|
scponly
|
scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs …
|
NVD-CWE-Other
|
CVE-2002-1469
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270353
|
2.1 |
LOW
|
nullsoft
|
shoutcast_server
|
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log…
|
NVD-CWE-Other
|
CVE-2002-1470
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270354
|
5.0 |
MEDIUM
|
ximian
|
evolution
|
The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote att…
|
NVD-CWE-Other
|
CVE-2002-1471
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270355
|
7.2 |
HIGH
|
xfree86_project
|
x11r6
|
Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that poi…
|
NVD-CWE-Other
|
CVE-2002-1472
|
2008-09-6 05:30 |
2003-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270356
|
4.6 |
MEDIUM
|
hp
|
hp-ux
|
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2002-1473
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270357
|
5.0 |
MEDIUM
|
hp
|
tru64
|
Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2002-1474
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270358
|
5.0 |
MEDIUM
|
hp
|
tru64
|
Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service.
|
NVD-CWE-Other
|
CVE-2002-1475
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270359
|
4.6 |
MEDIUM
|
netbsd
|
netbsd
|
Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a us…
|
NVD-CWE-Other
|
CVE-2002-1476
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270360
|
6.8 |
MEDIUM
|
phpgb
|
phpgb
|
Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the ent…
|
NVD-CWE-Other
|
CVE-2002-1480
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270361
|
7.5 |
HIGH
|
phpgb
|
phpgb
|
savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modif…
|
NVD-CWE-Other
|
CVE-2002-1481
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270362
|
10.0 |
HIGH
|
phpgb
|
phpgb
|
SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.
|
NVD-CWE-Other
|
CVE-2002-1482
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270363
|
5.0 |
MEDIUM
|
db4web
|
db4web
|
db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absol…
|
NVD-CWE-Other
|
CVE-2002-1483
|
2008-09-6 05:30 |
2003-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270364
|
5.0 |
MEDIUM
|
cerulean_studios
|
trillian
|
The AIM component of Trillian 0.73 and 0.74 allows remote attackers to cause a denial of service (crash) via certain strings such as "P > O < C".
|
NVD-CWE-Other
|
CVE-2002-1485
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270365
|
7.5 |
HIGH
|
cerulean_studios
|
trillian
|
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response …
|
NVD-CWE-Other
|
CVE-2002-1486
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270366
|
5.0 |
MEDIUM
|
cerulean_studios
|
trillian
|
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, …
|
NVD-CWE-Other
|
CVE-2002-1487
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270367
|
5.0 |
MEDIUM
|
cerulean_studios
|
trillian
|
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian u…
|
NVD-CWE-Other
|
CVE-2002-1488
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270368
|
7.5 |
HIGH
|
planetdns
|
planetweb
|
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.
|
NVD-CWE-Other
|
CVE-2002-1489
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270369
|
2.1 |
LOW
|
netbsd
|
netbsd
|
NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the TIOCSCTTY ioctl, which causes an integer overflow in a structure counter and se…
|
NVD-CWE-Other
|
CVE-2002-1490
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270370
|
5.0 |
MEDIUM
|
cisco
|
vpn_5000_client
|
The Cisco VPN 5000 Client for MacOS before 5.2.2 records the most recently used login password in plaintext when saving "Default Connection" settings, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-1491
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270371
|
7.2 |
HIGH
|
cisco
|
vpn_5000_client
|
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.
|
NVD-CWE-Other
|
CVE-2002-1492
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270372
|
4.3 |
MEDIUM
|
aestiva
|
html_os
|
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script…
|
NVD-CWE-Other
|
CVE-2002-1494
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270373
|
4.3 |
MEDIUM
|
rudi_benkovic
|
jawmail
|
Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that a…
|
NVD-CWE-Other
|
CVE-2002-1495
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270374
|
7.5 |
HIGH
|
nulllogic
|
null_httpd
|
Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header.
|
NVD-CWE-Other
|
CVE-2002-1496
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270375
|
5.0 |
MEDIUM
|
trevor_lee
|
swserver
|
Directory traversal vulnerability in SWServer 2.2 and earlier allows remote attackers to read arbitrary files via a URL containing .. sequences with "/" or "\" characters.
|
NVD-CWE-Other
|
CVE-2002-1498
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270376
|
7.5 |
HIGH
|
factosystem
|
factosystem_weblog
|
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid par…
|
NVD-CWE-Other
|
CVE-2002-1499
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270377
|
7.2 |
HIGH
|
netbsd
|
netbsd
|
Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which pro…
|
NVD-CWE-Other
|
CVE-2002-1500
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270378
|
5.0 |
MEDIUM
|
enterasys
|
smartswitch_ssr8000
|
The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078.
|
NVD-CWE-Other
|
CVE-2002-1501
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270379
|
2.1 |
LOW
|
dave_brul
|
xbreaky
|
Symbolic link vulnerability in xbreaky before 0.5.5 allows local users to overwrite arbitrary files via a symlink from the user's .breakyhighscores file to the target file.
|
NVD-CWE-Other
|
CVE-2002-1502
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270380
|
7.2 |
HIGH
|
afd
|
afd
|
Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdc…
|
NVD-CWE-Other
|
CVE-2002-1503
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270381
|
5.0 |
MEDIUM
|
radiobird_software
|
webserver_4_everyone
|
Directory traversal vulnerability in WebServer 4 Everyone 1.22 allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a URL.
|
NVD-CWE-Other
|
CVE-2002-1504
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270382
|
7.5 |
HIGH
|
woltlab
|
burning_board
|
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.
|
NVD-CWE-Other
|
CVE-2002-1505
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270383
|
7.2 |
HIGH
|
jacques_gelinas
|
linuxconf
|
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated.
|
NVD-CWE-Other
|
CVE-2002-1506
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270384
|
5.0 |
MEDIUM
|
epic_games
|
unreal_tournament_server
|
Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports 7778 or 10777.
|
NVD-CWE-Other
|
CVE-2002-1507
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270385
|
10.0 |
HIGH
|
xfree86_project
|
x11r6
|
xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.
|
NVD-CWE-Other
|
CVE-2002-1510
|
2008-09-6 05:30 |
2003-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270386
|
6.2 |
MEDIUM
|
tolis_group
|
bru
|
xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file.
|
NVD-CWE-Other
|
CVE-2002-1512
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270387
|
4.6 |
MEDIUM
|
compaq
|
tcp-ip_services
|
The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions becau…
|
NVD-CWE-Other
|
CVE-2002-1513
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270388
|
7.2 |
HIGH
|
borland_software
|
interbase
|
gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.
|
NVD-CWE-Other
|
CVE-2002-1514
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270389
|
5.0 |
MEDIUM
|
coolforum
|
coolforum
|
Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter.
|
NVD-CWE-Other
|
CVE-2002-1515
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270390
|
4.6 |
MEDIUM
|
sgi
|
freeware irix
|
fsr_efs in IRIX 6.5 allows local users to conduct unauthorized file activities via a symlink attack, possibly via the .fsrlast file.
|
NVD-CWE-Other
|
CVE-2002-1517
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270391
|
3.6 |
LOW
|
sgi
|
irix
|
mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local users to modify files and directories.
|
NVD-CWE-Other
|
CVE-2002-1518
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270392
|
10.0 |
HIGH
|
rapidstream watchguard
|
rapidstream firebox
|
Format string vulnerability in the CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, allows remote attackers to cause a denial of service and possibly execute arb…
|
NVD-CWE-Other
|
CVE-2002-1519
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270393
|
10.0 |
HIGH
|
rapidstream watchguard
|
rapidstream firebox
|
The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows …
|
NVD-CWE-Other
|
CVE-2002-1520
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270394
|
2.1 |
LOW
|
mdg_computer_services
|
web_server_4d
|
Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-1521
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270395
|
5.0 |
MEDIUM
|
cooolsoft
|
powerftp
|
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.
|
NVD-CWE-Other
|
CVE-2002-1522
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270396
|
5.0 |
MEDIUM
|
daniel_arenz
|
mini_server
|
Directory traversal vulnerability in Daniel Arenz Mini Server 2.1.6 allows remote attackers to read arbitrary files via (1) ../ (dot-dot slash) or (2) ..\ (dot-dot backslash) sequences.
|
NVD-CWE-Other
|
CVE-2002-1523
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270397
|
7.5 |
HIGH
|
nullsoft
|
winamp
|
Buffer overflow in XML parser in wsabi.dll of Winamp 3 (1.0.0.488) allows remote attackers to execute arbitrary code via a skin file (.wal) with a long include file tag.
|
NVD-CWE-Other
|
CVE-2002-1524
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270398
|
5.0 |
MEDIUM
|
astaware sun
|
searchdisc sunone_starter_kit
|
Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or …
|
NVD-CWE-Other
|
CVE-2002-1525
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270399
|
4.3 |
MEDIUM
|
emumail
|
emu_webmail
|
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field.
|
NVD-CWE-Other
|
CVE-2002-1526
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270400
|
5.0 |
MEDIUM
|
emumail
|
emu_webmail
|
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error tha…
|
NVD-CWE-Other
|
CVE-2002-1527
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|