276501
|
5.0 |
MEDIUM
|
ultrafunk
|
popcorn
|
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Date field that is converted into a year greater than 2037.
|
NVD-CWE-Other
|
CVE-2002-1045
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276502
|
5.0 |
MEDIUM
|
watchguard
|
firebox soho_firewall
|
Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to…
|
NVD-CWE-Other
|
CVE-2002-1046
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276503
|
7.5 |
HIGH
|
watchguard
|
soho_firewall
|
The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name.
|
NVD-CWE-Other
|
CVE-2002-1047
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276504
|
7.5 |
HIGH
|
hp
|
jetdirect
|
HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0.
|
NVD-CWE-Other
|
CVE-2002-1048
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276505
|
5.0 |
MEDIUM
|
hylafax
|
hylafax
|
Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element.
|
NVD-CWE-Other
|
CVE-2002-1049
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276506
|
7.5 |
HIGH
|
hylafax
|
hylafax
|
Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data.
|
NVD-CWE-Other
|
CVE-2002-1050
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276507
|
6.8 |
MEDIUM
|
w3c
|
jigsaw
|
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed…
|
NVD-CWE-Other
|
CVE-2002-1053
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276508
|
5.0 |
MEDIUM
|
brother
|
nc-3100h
|
Buffer overflow in administrative web server for Brother NC-3100h printer allows remote attackers to cause a denial of service via a long password.
|
NVD-CWE-Other
|
CVE-2002-1055
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276509
|
7.5 |
HIGH
|
smartmax_software
|
mailmax
|
Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command.
|
NVD-CWE-Other
|
CVE-2002-1057
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276510
|
10.0 |
HIGH
|
cobalt
|
qube
|
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cook…
|
NVD-CWE-Other
|
CVE-2002-1058
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276511
|
4.3 |
MEDIUM
|
bluecoat
|
cacheos
|
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers…
|
NVD-CWE-Other
|
CVE-2002-1060
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276512
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP…
|
NVD-CWE-Other
|
CVE-2002-1061
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276513
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.
|
NVD-CWE-Other
|
CVE-2002-1062
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276514
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV requests, which consumes a…
|
NVD-CWE-Other
|
CVE-2002-1063
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276515
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
|
NVD-CWE-Other
|
CVE-2002-1064
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276516
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute…
|
NVD-CWE-Other
|
CVE-2002-1065
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276517
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command t…
|
NVD-CWE-Other
|
CVE-2002-1066
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276518
|
5.0 |
MEDIUM
|
seh
|
ic9_pocket_print_server_firmware
|
Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buf…
|
NVD-CWE-Other
|
CVE-2002-1067
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276519
|
7.5 |
HIGH
|
php-wiki
|
php-wiki
|
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.
|
NVD-CWE-Other
|
CVE-2002-1070
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276520
|
5.0 |
MEDIUM
|
zyxel
|
prestige
|
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.
|
NVD-CWE-Other
|
CVE-2002-1071
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276521
|
5.0 |
MEDIUM
|
zyxel
|
prestige
|
ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.
|
NVD-CWE-Other
|
CVE-2002-1072
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276522
|
7.5 |
HIGH
|
atrium_software
|
mercur_mailserver
|
Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.
|
NVD-CWE-Other
|
CVE-2002-1073
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276523
|
7.5 |
HIGH
|
david_harris
|
pegasus_mail
|
Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.
|
NVD-CWE-Other
|
CVE-2002-1075
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276524
|
7.5 |
HIGH
|
ipswitch
|
imail
|
Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.
|
NVD-CWE-Other
|
CVE-2002-1076
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276525
|
5.0 |
MEDIUM
|
ipswitch
|
imail
|
IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.
|
NVD-CWE-Other
|
CVE-2002-1077
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276526
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters.
|
NVD-CWE-Other
|
CVE-2002-1078
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276527
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-1079
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276528
|
7.5 |
HIGH
|
aprelium_technologies
|
abyss_web_server
|
The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.…
|
NVD-CWE-Other
|
CVE-2002-1080
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276529
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.
|
NVD-CWE-Other
|
CVE-2002-1081
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276530
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.
|
NVD-CWE-Other
|
CVE-2002-1082
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276531
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or …
|
NVD-CWE-Other
|
CVE-2002-1083
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276532
|
6.4 |
MEDIUM
|
visualshapers
|
ezcontents
|
The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted inform…
|
NVD-CWE-Other
|
CVE-2002-1084
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276533
|
7.5 |
HIGH
|
visualshapers
|
ezcontents
|
Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.
|
NVD-CWE-Other
|
CVE-2002-1085
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276534
|
7.5 |
HIGH
|
visualshapers
|
ezcontents
|
Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.
|
NVD-CWE-Other
|
CVE-2002-1086
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276535
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upl…
|
NVD-CWE-Other
|
CVE-2002-1087
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276536
|
7.5 |
HIGH
|
novell
|
groupwise
|
Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
|
NVD-CWE-Other
|
CVE-2002-1088
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276537
|
5.0 |
MEDIUM
|
oracle
|
application_server reports
|
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
|
NVD-CWE-Other
|
CVE-2002-1089
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276538
|
7.5 |
HIGH
|
libesmtp
|
libesmtp
|
Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via lon…
|
NVD-CWE-Other
|
CVE-2002-1090
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276539
|
7.2 |
HIGH
|
purity
|
purity
|
Multiple buffer overflows in purity 1-16 allow local users to gain privileges and modify high scores tables.
|
NVD-CWE-Other
|
CVE-2002-1124
|
2008-09-6 05:29 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276540
|
7.2 |
HIGH
|
digital
|
osf_1
|
Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.
|
NVD-CWE-Other
|
CVE-2002-1127
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276541
|
7.5 |
HIGH
|
squirrelmail
|
squirrelmail
|
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) he…
|
NVD-CWE-Other
|
CVE-2002-1131
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276542
|
5.0 |
MEDIUM
|
squirrelmail
|
squirrelmail
|
SquirrelMail 1.2.7 and earlier allows remote attackers to determine the absolute pathname of the options.php script via a malformed optpage file argument, which generates an error message when the fi…
|
NVD-CWE-Other
|
CVE-2002-1132
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276543
|
5.0 |
MEDIUM
|
stephen_turner
|
analog
|
anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the comm…
|
NVD-CWE-Other
|
CVE-2002-1154
|
2008-09-6 05:29 |
2002-10-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276544
|
7.5 |
HIGH
|
mod_ssl
|
mod_ssl
|
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web sit…
|
NVD-CWE-Other
|
CVE-2002-1157
|
2008-09-6 05:29 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276545
|
7.5 |
HIGH
|
checkpoint
|
check_point_vpn firewall-1 next_generation
|
Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file.
|
NVD-CWE-Other
|
CVE-2002-0428
|
2008-09-6 05:28 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276546
|
5.0 |
MEDIUM
|
dave_lawrence
|
xtux
|
XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.
|
NVD-CWE-Other
|
CVE-2002-0431
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276547
|
10.0 |
HIGH
|
citadel
|
ux
|
Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attacks …
|
NVD-CWE-Other
|
CVE-2002-0432
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276548
|
5.0 |
MEDIUM
|
pi3
|
pi3web
|
Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.
|
NVD-CWE-Other
|
CVE-2002-0433
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276549
|
10.0 |
HIGH
|
marcus_s._xenakis
|
directory.php
|
Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.
|
NVD-CWE-Other
|
CVE-2002-0434
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276550
|
1.2 |
LOW
|
gnu
|
fileutils
|
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils …
|
NVD-CWE-Other
|
CVE-2002-0435
|
2008-09-6 05:28 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|