276601
|
7.5 |
HIGH
|
blackboard
|
blackboard
|
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInf…
|
NVD-CWE-Other
|
CVE-2002-1007
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276602
|
7.5 |
HIGH
|
summit_computer_networks
|
lil_http_server
|
Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlc…
|
NVD-CWE-Other
|
CVE-2002-1008
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276603
|
7.5 |
HIGH
|
summit_computer_networks
|
lil_http_server
|
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2…
|
NVD-CWE-Other
|
CVE-2002-1009
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276604
|
7.5 |
HIGH
|
lotus
|
domino_r4
|
Lotus Domino R4 allows remote attackers to bypass access restrictions for files in the web root via an HTTP request appended with a "?" character, which is treated as a wildcard character and bypasse…
|
NVD-CWE-Other
|
CVE-2002-1010
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276605
|
7.5 |
HIGH
|
ibm
|
tivoli_management_framework
|
Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via …
|
NVD-CWE-Other
|
CVE-2002-1011
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276606
|
7.5 |
HIGH
|
ibm
|
tivoli_management_framework
|
Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET …
|
NVD-CWE-Other
|
CVE-2002-1012
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276607
|
7.2 |
HIGH
|
inktomi
|
media-ixt traffic_edge traffic_server
|
Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Media-IXT 3.0.4 allows local users to gain root privileges via a long -path argum…
|
NVD-CWE-Other
|
CVE-2002-1013
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276608
|
7.5 |
HIGH
|
realnetworks
|
realjukebox_2 realjukebox_2_plus realone_player
|
Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long val…
|
NVD-CWE-Other
|
CVE-2002-1014
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276609
|
7.5 |
HIGH
|
realnetworks
|
realjukebox_2 realjukebox_2_plus realone_player
|
RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini fil…
|
NVD-CWE-Other
|
CVE-2002-1015
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276610
|
4.6 |
MEDIUM
|
adobe
|
digital_editions
|
Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files, performing the operations, and restoring the original data files.
|
NVD-CWE-Other
|
CVE-2002-1016
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276611
|
2.1 |
LOW
|
adobe
|
digital_editions
|
Adobe eBook Reader 2.1 and 2.2 allows a user to copy eBooks to other systems by using the backup feature, capturing the encryption Challenge, and using the appropriate hash function to generate the a…
|
NVD-CWE-Other
|
CVE-2002-1017
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276612
|
5.0 |
MEDIUM
|
working_resources_inc.
|
badblue
|
BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.
|
NVD-CWE-Other
|
CVE-2002-1021
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276613
|
7.5 |
HIGH
|
working_resources_inc.
|
badblue
|
BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-1022
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276614
|
5.0 |
MEDIUM
|
working_resources_inc.
|
badblue
|
BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.
|
NVD-CWE-Other
|
CVE-2002-1023
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276615
|
5.0 |
MEDIUM
|
macromedia
|
jrun
|
JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP file unparsed.
|
NVD-CWE-Other
|
CVE-2002-1025
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276616
|
5.0 |
MEDIUM
|
macromedia
|
sitespring
|
Macromedia Sitespring 1.2.0 (277.1) using Sybase runtime engine 7.0.2.1480 allows remote attackers to cause a denial of service (crash) via a long malformed request to TCP port 2500, possibly trigger…
|
NVD-CWE-Other
|
CVE-2002-1026
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276617
|
7.5 |
HIGH
|
macromedia
|
sitespring
|
Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 50…
|
NVD-CWE-Other
|
CVE-2002-1027
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276618
|
5.0 |
MEDIUM
|
oddsock
|
song_requester
|
Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash) via long arguments.
|
NVD-CWE-Other
|
CVE-2002-1028
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276619
|
5.0 |
MEDIUM
|
worldspan
|
res_manager
|
Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to TCP port 17990.
|
NVD-CWE-Other
|
CVE-2002-1029
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276620
|
2.6 |
LOW
|
bea
|
weblogic_server
|
Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections.
|
NVD-CWE-Other
|
CVE-2002-1030
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276621
|
5.0 |
MEDIUM
|
key_focus
|
kf_web_server
|
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.
|
NVD-CWE-Other
|
CVE-2002-1031
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276622
|
7.5 |
HIGH
|
key_focus
|
kf_web_server
|
Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.
|
NVD-CWE-Other
|
CVE-2002-1032
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276623
|
5.0 |
MEDIUM
|
sun
|
i-runbook
|
Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot variant) in the argument.
|
NVD-CWE-Other
|
CVE-2002-1033
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276624
|
10.0 |
HIGH
|
sun
|
i-runbook
|
none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument.
|
NVD-CWE-Other
|
CVE-2002-1034
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276625
|
5.0 |
MEDIUM
|
omnicron
|
omnihttpd
|
Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number.
|
NVD-CWE-Other
|
CVE-2002-1035
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276626
|
7.5 |
HIGH
|
zoltan_milosevic
|
fluid_dynamics_search_engine
|
Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.
|
NVD-CWE-Other
|
CVE-2002-1036
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276627
|
5.0 |
MEDIUM
|
ibm
|
aix
|
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
|
NVD-CWE-Other
|
CVE-2002-1040
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276628
|
5.0 |
MEDIUM
|
netscape sun
|
enterprise_server iplanet_web_server one_application_server one_web_server
|
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read a…
|
NVD-CWE-Other
|
CVE-2002-1042
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276629
|
5.0 |
MEDIUM
|
ultrafunk
|
popcorn
|
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").
|
NVD-CWE-Other
|
CVE-2002-1043
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276630
|
7.5 |
HIGH
|
ultrafunk
|
popcorn
|
Buffer overflow in Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Subject field.
|
NVD-CWE-Other
|
CVE-2002-1044
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276631
|
5.0 |
MEDIUM
|
ultrafunk
|
popcorn
|
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Date field that is converted into a year greater than 2037.
|
NVD-CWE-Other
|
CVE-2002-1045
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276632
|
5.0 |
MEDIUM
|
watchguard
|
firebox soho_firewall
|
Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to…
|
NVD-CWE-Other
|
CVE-2002-1046
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276633
|
7.5 |
HIGH
|
watchguard
|
soho_firewall
|
The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name.
|
NVD-CWE-Other
|
CVE-2002-1047
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276634
|
7.5 |
HIGH
|
hp
|
jetdirect
|
HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0.
|
NVD-CWE-Other
|
CVE-2002-1048
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276635
|
5.0 |
MEDIUM
|
hylafax
|
hylafax
|
Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element.
|
NVD-CWE-Other
|
CVE-2002-1049
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276636
|
7.5 |
HIGH
|
hylafax
|
hylafax
|
Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data.
|
NVD-CWE-Other
|
CVE-2002-1050
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276637
|
6.8 |
MEDIUM
|
w3c
|
jigsaw
|
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed…
|
NVD-CWE-Other
|
CVE-2002-1053
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276638
|
5.0 |
MEDIUM
|
brother
|
nc-3100h
|
Buffer overflow in administrative web server for Brother NC-3100h printer allows remote attackers to cause a denial of service via a long password.
|
NVD-CWE-Other
|
CVE-2002-1055
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276639
|
7.5 |
HIGH
|
smartmax_software
|
mailmax
|
Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command.
|
NVD-CWE-Other
|
CVE-2002-1057
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276640
|
10.0 |
HIGH
|
cobalt
|
qube
|
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cook…
|
NVD-CWE-Other
|
CVE-2002-1058
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276641
|
4.3 |
MEDIUM
|
bluecoat
|
cacheos
|
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers…
|
NVD-CWE-Other
|
CVE-2002-1060
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276642
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP…
|
NVD-CWE-Other
|
CVE-2002-1061
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276643
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.
|
NVD-CWE-Other
|
CVE-2002-1062
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276644
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV requests, which consumes a…
|
NVD-CWE-Other
|
CVE-2002-1063
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276645
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
|
NVD-CWE-Other
|
CVE-2002-1064
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276646
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute…
|
NVD-CWE-Other
|
CVE-2002-1065
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276647
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command t…
|
NVD-CWE-Other
|
CVE-2002-1066
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276648
|
5.0 |
MEDIUM
|
seh
|
ic9_pocket_print_server_firmware
|
Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buf…
|
NVD-CWE-Other
|
CVE-2002-1067
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276649
|
7.5 |
HIGH
|
php-wiki
|
php-wiki
|
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.
|
NVD-CWE-Other
|
CVE-2002-1070
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
276650
|
5.0 |
MEDIUM
|
zyxel
|
prestige
|
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.
|
NVD-CWE-Other
|
CVE-2002-1071
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|