276251
|
7.5 |
HIGH
|
kde
|
kde
|
Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a denial of service or execute arbitrary code via a modified .ps (PostScri…
|
NVD-CWE-Other
|
CVE-2002-1223
|
2008-09-6 05:30 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276252
|
5.0 |
MEDIUM
|
kde
|
kde
|
Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.
|
NVD-CWE-Other
|
CVE-2002-1224
|
2008-09-6 05:30 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276253
|
7.5 |
HIGH
|
pam
|
pam
|
PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.
|
NVD-CWE-Other
|
CVE-2002-1227
|
2008-09-6 05:30 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276254
|
10.0 |
HIGH
|
log2mail
|
log2mail
|
Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message.
|
NVD-CWE-Other
|
CVE-2002-1251
|
2008-09-6 05:30 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276255
|
7.2 |
HIGH
|
abuse
|
abuse
|
Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute …
|
NVD-CWE-Other
|
CVE-2002-1253
|
2008-09-6 05:30 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276256
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem.
|
NVD-CWE-Other
|
CVE-2002-1269
|
2008-09-6 05:30 |
2002-12-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276257
|
4.3 |
MEDIUM
|
squirrelmail
|
squirrelmail
|
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving …
|
NVD-CWE-Other
|
CVE-2002-1276
|
2008-09-6 05:30 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276258
|
7.5 |
HIGH
|
windowmaker
|
windowmaker
|
Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and…
|
NVD-CWE-Other
|
CVE-2002-1277
|
2008-09-6 05:30 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276259
|
7.2 |
HIGH
|
hp
|
hp-ux
|
Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."
|
NVD-CWE-Other
|
CVE-2002-1406
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276260
|
7.5 |
HIGH
|
hp
|
openview_emanate_snmp_agent vvos
|
Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) "'read-only' community access," and/or (2) an e…
|
NVD-CWE-Other
|
CVE-2002-1408
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276261
|
7.5 |
HIGH
|
ben_chivers easy_scripts_archive
|
ben_chivers_guestbook easy_guestbook
|
Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access o…
|
NVD-CWE-Other
|
CVE-2002-1410
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276262
|
5.0 |
MEDIUM
|
duma
|
photo_gallery_system
|
Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.
|
NVD-CWE-Other
|
CVE-2002-1411
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276263
|
7.5 |
HIGH
|
novell
|
netware
|
RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.
|
NVD-CWE-Other
|
CVE-2002-1413
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276264
|
5.0 |
MEDIUM
|
webeasymail
|
webeasymail
|
Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in …
|
NVD-CWE-Other
|
CVE-2002-1415
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276265
|
5.0 |
MEDIUM
|
webeasymail
|
webeasymail
|
The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct b…
|
NVD-CWE-Other
|
CVE-2002-1416
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276266
|
5.0 |
MEDIUM
|
novell
|
small_business_suite netware
|
Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL…
|
NVD-CWE-Other
|
CVE-2002-1417
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276267
|
5.0 |
MEDIUM
|
novell
|
small_business_suite netware
|
Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (A…
|
NVD-CWE-Other
|
CVE-2002-1418
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276268
|
7.5 |
HIGH
|
sgi
|
irix
|
The upgrade of IRIX on Origin 3000 to 6.5.13 through 6.5.16 changes the MAC address of the system, which could modify intended access restrictions that are based on a MAC address.
|
NVD-CWE-Other
|
CVE-2002-1419
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276269
|
7.5 |
HIGH
|
ilia_alshanetsky
|
fudforum
|
SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php.
|
NVD-CWE-Other
|
CVE-2002-1421
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276270
|
5.0 |
MEDIUM
|
ilia_alshanetsky
|
fudforum
|
admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters.
|
NVD-CWE-Other
|
CVE-2002-1422
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276271
|
5.0 |
MEDIUM
|
ilia_alshanetsky
|
fudforum
|
tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter.
|
NVD-CWE-Other
|
CVE-2002-1423
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276272
|
5.0 |
MEDIUM
|
john_g._myers
|
mpack
|
Buffer overflow in munpack in mpack 1.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2002-1424
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276273
|
6.4 |
MEDIUM
|
john_g._myers
|
mpack
|
Directory traversal vulnerability in munpack in mpack 1.5 and earlier allows remote attackers to create new files in the parent directory via a ../ (dot-dot) sequence in the filename to be extracted.
|
NVD-CWE-Other
|
CVE-2002-1425
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276274
|
7.8 |
HIGH
|
hp
|
procurve_switch_4000m
|
HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-1426
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276275
|
7.5 |
HIGH
|
easy_scripts_archive
|
advanced_easy_homepage_creator easy_homepage_creator
|
The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users.
|
NVD-CWE-Other
|
CVE-2002-1427
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276276
|
10.0 |
HIGH
|
dotproject
|
dotproject
|
index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.
|
NVD-CWE-Other
|
CVE-2002-1428
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276277
|
5.0 |
MEDIUM
|
synthetic_reality
|
sympoll
|
Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters.
|
NVD-CWE-Other
|
CVE-2002-1430
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276278
|
7.5 |
HIGH
|
belkin
|
f5d5230-4_4-port_cable_dsl_gateway_router
|
Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host…
|
NVD-CWE-Other
|
CVE-2002-1431
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276279
|
5.0 |
MEDIUM
|
kerio
|
kerio_mailserver
|
Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.
|
NVD-CWE-Other
|
CVE-2002-1433
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276280
|
6.8 |
MEDIUM
|
kerio
|
kerio_mailserver
|
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
|
NVD-CWE-Other
|
CVE-2002-1434
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276281
|
7.5 |
HIGH
|
achievo
|
achievo
|
class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url_fopen' setting is enabled via a URL in the config…
|
NVD-CWE-Other
|
CVE-2002-1435
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276282
|
7.5 |
HIGH
|
novell
|
netware
|
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.
|
NVD-CWE-Other
|
CVE-2002-1436
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276283
|
5.0 |
MEDIUM
|
novell
|
netware
|
Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-enc…
|
NVD-CWE-Other
|
CVE-2002-1437
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276284
|
5.0 |
MEDIUM
|
novell
|
netware
|
The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to obtain Perl version information via the -v option.
|
NVD-CWE-Other
|
CVE-2002-1438
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276285
|
4.6 |
MEDIUM
|
hp
|
virtualvault vvos
|
Unknown vulnerability related to stack corruption in the TGA daemon for HP-UX 11.04 (VVOS) Virtualvault 4.0, 4.5, and 4.6 may allow attackers to obtain access to system files.
|
NVD-CWE-Other
|
CVE-2002-1439
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276286
|
10.0 |
HIGH
|
gateway
|
gs-400
|
The Gateway GS-400 server has a default root password of "0001n" that can not be changed via the administrative interface, which can allow attackers to gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-1440
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276287
|
7.5 |
HIGH
|
tomahawk_technologies
|
steelarrow
|
Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) …
|
NVD-CWE-Other
|
CVE-2002-1441
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276288
|
7.5 |
HIGH
|
google
|
toolbar
|
The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a …
|
NVD-CWE-Other
|
CVE-2002-1442
|
2008-09-6 05:30 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276289
|
4.3 |
MEDIUM
|
w3c
|
cern_httpd
|
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inser…
|
NVD-CWE-Other
|
CVE-2002-1445
|
2008-09-6 05:30 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276290
|
5.0 |
MEDIUM
|
ncipher
|
pkcs_11_library
|
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signatur…
|
NVD-CWE-Other
|
CVE-2002-1446
|
2008-09-6 05:30 |
2002-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276291
|
7.2 |
HIGH
|
cisco
|
vpn_client
|
Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.
|
NVD-CWE-Other
|
CVE-2002-1447
|
2008-09-6 05:30 |
2002-05-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276292
|
7.5 |
HIGH
|
avaya
|
cajun_m770-atm cajun_p130 cajun_p330
|
An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.
|
NVD-CWE-Other
|
CVE-2002-1448
|
2008-09-6 05:30 |
2002-07-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276293
|
5.0 |
MEDIUM
|
ibm
|
u2_universe
|
IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a query with an invalid link between tables, possibly via a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-1450
|
2008-09-6 05:30 |
2002-07-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276294
|
5.0 |
MEDIUM
|
desiderata_software
|
blazix
|
Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character.
|
NVD-CWE-Other
|
CVE-2002-1451
|
2008-09-6 05:30 |
2002-08-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276295
|
4.3 |
MEDIUM
|
omnicron
|
omnihttpd
|
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
|
NVD-CWE-Other
|
CVE-2002-1455
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276296
|
7.5 |
HIGH
|
leszek_krupinski
|
l-forum
|
SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.
|
NVD-CWE-Other
|
CVE-2002-1457
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276297
|
7.5 |
HIGH
|
leszek_krupinski
|
l-forum
|
Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields includin…
|
NVD-CWE-Other
|
CVE-2002-1458
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276298
|
7.5 |
HIGH
|
leszek_krupinski
|
l-forum
|
Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields includi…
|
NVD-CWE-Other
|
CVE-2002-1459
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276299
|
5.0 |
MEDIUM
|
leszek_krupinski
|
l-forum
|
L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which…
|
NVD-CWE-Other
|
CVE-2002-1460
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276300
|
7.5 |
HIGH
|
webscriptworld
|
web_shop_manager
|
Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.
|
NVD-CWE-Other
|
CVE-2002-1461
|
2008-09-6 05:30 |
2003-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|