270551
|
7.5 |
HIGH
|
hylafax
|
hylafax
|
Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data.
|
NVD-CWE-Other
|
CVE-2002-1050
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270552
|
6.8 |
MEDIUM
|
w3c
|
jigsaw
|
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed…
|
NVD-CWE-Other
|
CVE-2002-1053
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270553
|
5.0 |
MEDIUM
|
brother
|
nc-3100h
|
Buffer overflow in administrative web server for Brother NC-3100h printer allows remote attackers to cause a denial of service via a long password.
|
NVD-CWE-Other
|
CVE-2002-1055
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270554
|
7.5 |
HIGH
|
smartmax_software
|
mailmax
|
Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command.
|
NVD-CWE-Other
|
CVE-2002-1057
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270555
|
10.0 |
HIGH
|
cobalt
|
qube
|
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cook…
|
NVD-CWE-Other
|
CVE-2002-1058
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270556
|
4.3 |
MEDIUM
|
bluecoat
|
cacheos
|
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers…
|
NVD-CWE-Other
|
CVE-2002-1060
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270557
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP…
|
NVD-CWE-Other
|
CVE-2002-1061
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270558
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.
|
NVD-CWE-Other
|
CVE-2002-1062
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270559
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV requests, which consumes a…
|
NVD-CWE-Other
|
CVE-2002-1063
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270560
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
|
NVD-CWE-Other
|
CVE-2002-1064
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270561
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute…
|
NVD-CWE-Other
|
CVE-2002-1065
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270562
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command t…
|
NVD-CWE-Other
|
CVE-2002-1066
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270563
|
5.0 |
MEDIUM
|
seh
|
ic9_pocket_print_server_firmware
|
Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buf…
|
NVD-CWE-Other
|
CVE-2002-1067
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270564
|
7.5 |
HIGH
|
php-wiki
|
php-wiki
|
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.
|
NVD-CWE-Other
|
CVE-2002-1070
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270565
|
5.0 |
MEDIUM
|
zyxel
|
prestige
|
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.
|
NVD-CWE-Other
|
CVE-2002-1071
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270566
|
5.0 |
MEDIUM
|
zyxel
|
prestige
|
ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.
|
NVD-CWE-Other
|
CVE-2002-1072
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270567
|
7.5 |
HIGH
|
atrium_software
|
mercur_mailserver
|
Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.
|
NVD-CWE-Other
|
CVE-2002-1073
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270568
|
7.5 |
HIGH
|
david_harris
|
pegasus_mail
|
Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.
|
NVD-CWE-Other
|
CVE-2002-1075
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270569
|
7.5 |
HIGH
|
ipswitch
|
imail
|
Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.
|
NVD-CWE-Other
|
CVE-2002-1076
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270570
|
5.0 |
MEDIUM
|
ipswitch
|
imail
|
IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.
|
NVD-CWE-Other
|
CVE-2002-1077
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270571
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters.
|
NVD-CWE-Other
|
CVE-2002-1078
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270572
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-1079
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270573
|
7.5 |
HIGH
|
aprelium_technologies
|
abyss_web_server
|
The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.…
|
NVD-CWE-Other
|
CVE-2002-1080
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270574
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.
|
NVD-CWE-Other
|
CVE-2002-1081
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270575
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.
|
NVD-CWE-Other
|
CVE-2002-1082
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270576
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or …
|
NVD-CWE-Other
|
CVE-2002-1083
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270577
|
6.4 |
MEDIUM
|
visualshapers
|
ezcontents
|
The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted inform…
|
NVD-CWE-Other
|
CVE-2002-1084
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270578
|
7.5 |
HIGH
|
visualshapers
|
ezcontents
|
Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.
|
NVD-CWE-Other
|
CVE-2002-1085
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270579
|
7.5 |
HIGH
|
visualshapers
|
ezcontents
|
Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.
|
NVD-CWE-Other
|
CVE-2002-1086
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270580
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upl…
|
NVD-CWE-Other
|
CVE-2002-1087
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270581
|
7.5 |
HIGH
|
novell
|
groupwise
|
Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
|
NVD-CWE-Other
|
CVE-2002-1088
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270582
|
5.0 |
MEDIUM
|
oracle
|
application_server reports
|
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
|
NVD-CWE-Other
|
CVE-2002-1089
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270583
|
7.5 |
HIGH
|
libesmtp
|
libesmtp
|
Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via lon…
|
NVD-CWE-Other
|
CVE-2002-1090
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270584
|
7.2 |
HIGH
|
purity
|
purity
|
Multiple buffer overflows in purity 1-16 allow local users to gain privileges and modify high scores tables.
|
NVD-CWE-Other
|
CVE-2002-1124
|
2008-09-6 05:29 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270585
|
7.2 |
HIGH
|
digital
|
osf_1
|
Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.
|
NVD-CWE-Other
|
CVE-2002-1127
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270586
|
7.5 |
HIGH
|
squirrelmail
|
squirrelmail
|
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) he…
|
NVD-CWE-Other
|
CVE-2002-1131
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270587
|
5.0 |
MEDIUM
|
squirrelmail
|
squirrelmail
|
SquirrelMail 1.2.7 and earlier allows remote attackers to determine the absolute pathname of the options.php script via a malformed optpage file argument, which generates an error message when the fi…
|
NVD-CWE-Other
|
CVE-2002-1132
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270588
|
5.0 |
MEDIUM
|
stephen_turner
|
analog
|
anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the comm…
|
NVD-CWE-Other
|
CVE-2002-1154
|
2008-09-6 05:29 |
2002-10-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270589
|
7.5 |
HIGH
|
mod_ssl
|
mod_ssl
|
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web sit…
|
NVD-CWE-Other
|
CVE-2002-1157
|
2008-09-6 05:29 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270590
|
7.5 |
HIGH
|
checkpoint
|
check_point_vpn firewall-1 next_generation
|
Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file.
|
NVD-CWE-Other
|
CVE-2002-0428
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270591
|
5.0 |
MEDIUM
|
dave_lawrence
|
xtux
|
XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.
|
NVD-CWE-Other
|
CVE-2002-0431
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270592
|
10.0 |
HIGH
|
citadel
|
ux
|
Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attacks …
|
NVD-CWE-Other
|
CVE-2002-0432
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270593
|
5.0 |
MEDIUM
|
pi3
|
pi3web
|
Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.
|
NVD-CWE-Other
|
CVE-2002-0433
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270594
|
10.0 |
HIGH
|
marcus_s._xenakis
|
directory.php
|
Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.
|
NVD-CWE-Other
|
CVE-2002-0434
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270595
|
1.2 |
LOW
|
gnu
|
fileutils
|
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils …
|
NVD-CWE-Other
|
CVE-2002-0435
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270596
|
10.0 |
HIGH
|
stefan_frings
|
sms_server_tools
|
Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format…
|
NVD-CWE-Other
|
CVE-2002-0437
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270597
|
7.5 |
HIGH
|
caupo.net
|
cauposhop
|
Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by …
|
NVD-CWE-Other
|
CVE-2002-0439
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270598
|
5.0 |
MEDIUM
|
jerrett_taylor
|
php_imglist
|
Directory traversal vulnerability in imlist.php for Php Imglist allows remote attackers to read arbitrary code via a .. (dot dot) in the cwd parameter.
|
NVD-CWE-Other
|
CVE-2002-0441
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270599
|
7.2 |
HIGH
|
caldera
|
openserver
|
Buffer overflow in dlvr_audit for Caldera OpenServer 5.0.5 and 5.0.6 allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-0442
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
270600
|
7.5 |
HIGH
|
microsoft
|
windows_2000_terminal_services
|
Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL shar…
|
NVD-CWE-Other
|
CVE-2002-0444
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|