|
312501
|
7.5 |
HIGH
|
frederic_tyndiuk
|
eupload
|
eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.
|
NVD-CWE-Other
|
CVE-2002-1449
|
2008-09-11 04:14 |
2002-07-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312502
|
1.2 |
LOW
|
openldap
|
openldap
|
slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.
|
NVD-CWE-Other
|
CVE-2002-1508
|
2008-09-11 04:14 |
2003-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312503
|
3.6 |
LOW
|
redhat
|
linux
|
A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users in the same group to …
|
NVD-CWE-Other
|
CVE-2002-1509
|
2008-09-11 04:14 |
2003-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312504
|
5.0 |
MEDIUM
|
att tightvnc
|
vnc tightvnc
|
The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.
|
NVD-CWE-Other
|
CVE-2002-1511
|
2008-09-11 04:14 |
2003-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312505
|
4.6 |
MEDIUM
|
sgi
|
irix
|
rpcbind in SGI IRIX, when using the -w command line switch, allows local users to overwrite arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2002-1516
|
2008-09-11 04:14 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312506
|
7.2 |
HIGH
|
symantec
|
norton_antivirus
|
The client for Symantec Norton AntiVirus Corporate Edition 7.5.x before 7.5.1 Build 62 and 7.6.x before 7.6.1 Build 35a runs winhlp32 with raised privileges, which allows local users to gain privileg…
|
NVD-CWE-Other
|
CVE-2002-1540
|
2008-09-11 04:14 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312507
|
5.0 |
MEDIUM
|
cisco
|
vpn_client
|
Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Para…
|
NVD-CWE-Other
|
CVE-2002-0852
|
2008-09-11 04:13 |
2002-09-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312508
|
5.0 |
MEDIUM
|
cisco
|
vpn_client
|
Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a zero-length payload.
|
NVD-CWE-Other
|
CVE-2002-0853
|
2008-09-11 04:13 |
2002-09-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312509
|
5.0 |
MEDIUM
|
oracle
|
database_server oracle9i
|
SQL*NET listener for Oracle Net Oracle9i 9.0.x and 9.2 allows remote attackers to cause a denial of service (crash) via certain debug requests that are not properly handled by the debugging feature.
|
NVD-CWE-Other
|
CVE-2002-0856
|
2008-09-11 04:13 |
2002-09-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312510
|
7.5 |
HIGH
|
l2tpd
|
l2tpd
|
l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.
|
NVD-CWE-Other
|
CVE-2002-0872
|
2008-09-11 04:13 |
2002-09-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312511
|
5.0 |
MEDIUM
|
l2tpd
|
l2tpd
|
Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-0873
|
2008-09-11 04:13 |
2002-09-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312512
|
5.0 |
MEDIUM
|
redhat
|
interchange
|
Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2002-0874
|
2008-09-11 04:13 |
2002-09-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312513
|
2.1 |
LOW
|
sgi debian
|
fam irix debian_linux
|
Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.
|
NVD-CWE-Other
|
CVE-2002-0875
|
2008-09-11 04:13 |
2002-09-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312514
|
5.1 |
MEDIUM
|
cgiscript.net
|
cspassword
|
CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to g…
|
NVD-CWE-Other
|
CVE-2002-0920
|
2008-09-11 04:13 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312515
|
7.5 |
HIGH
|
cgiscript.net
|
csnews
|
CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability.
|
NVD-CWE-Other
|
CVE-2002-0924
|
2008-09-11 04:13 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312516
|
4.6 |
MEDIUM
|
ncipher
|
mscapi_csp
|
The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protecti…
|
NVD-CWE-Other
|
CVE-2002-0939
|
2008-09-11 04:13 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312517
|
4.6 |
MEDIUM
|
ncipher
|
mscapi_csp
|
domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lowe…
|
NVD-CWE-Other
|
CVE-2002-0940
|
2008-09-11 04:13 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312518
|
7.5 |
HIGH
|
scripts_for_educators
|
makebook
|
Scripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side includes (SSI) as the web server, via the (1) Name or (2) Email para…
|
NVD-CWE-Other
|
CVE-2002-0948
|
2008-09-11 04:13 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312519
|
7.5 |
HIGH
|
microsoft
|
file_transfer_manager
|
Buffer overflow in Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to execute arbitrary code via a long TS value.
|
NVD-CWE-Other
|
CVE-2002-0977
|
2008-09-11 04:13 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312520
|
5.0 |
MEDIUM
|
microsoft
|
file_transfer_manager
|
Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to upload or download arbitrary files to arbitrary locations via a man-in-the-middle attack with modified TGT …
|
NVD-CWE-Other
|
CVE-2002-0978
|
2008-09-11 04:13 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312521
|
7.2 |
HIGH
|
caldera
|
unixware openunix
|
Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line.
|
NVD-CWE-Other
|
CVE-2002-0981
|
2008-09-11 04:13 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312522
|
7.5 |
HIGH
|
light
|
light
|
The IRC script included in Light 2.7.x before 2.7.30p5, and 2.8.x before 2.8pre10, running EPIC allows remote attackers to execute arbitrary code if the user joins a channel whose topic includes EPIC…
|
NVD-CWE-Other
|
CVE-2002-0984
|
2008-09-11 04:13 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312523
|
7.2 |
HIGH
|
caldera
|
unixware openunix
|
X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0987
|
2008-09-11 04:13 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312524
|
10.0 |
HIGH
|
caldera
|
unixware openunix
|
Buffer overflow in X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1, possibly related to XBM/xkbcomp capabilities.
|
NVD-CWE-Other
|
CVE-2002-0988
|
2008-09-11 04:13 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312525
|
7.5 |
HIGH
|
iss
|
internet_scanner
|
Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers to execute arbitrary code via a long web server response.
|
NVD-CWE-Other
|
CVE-2002-1122
|
2008-09-11 04:13 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312526
|
7.2 |
HIGH
|
digital
|
osf_1 ultrix
|
Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.
|
NVD-CWE-Other
|
CVE-2002-1128
|
2008-09-11 04:13 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312527
|
5.0 |
MEDIUM
|
gnu
|
glibc
|
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a D…
|
NVD-CWE-Other
|
CVE-2002-1146
|
2008-09-11 04:13 |
2002-10-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312528
|
6.8 |
MEDIUM
|
ibm
|
websphere_caching_proxy_server
|
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-1167
|
2008-09-11 04:13 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312529
|
6.8 |
MEDIUM
|
ibm
|
websphere_caching_proxy_server
|
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that …
|
NVD-CWE-Other
|
CVE-2002-1168
|
2008-09-11 04:13 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312530
|
3.7 |
LOW
|
sun
|
cobalt_raq_2 cobalt_raq_3i cobalt_raq_4
|
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, follo…
|
NVD-CWE-Other
|
CVE-2002-0430
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312531
|
7.5 |
HIGH
|
trend_micro
|
interscan_viruswall
|
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header s…
|
NVD-CWE-Other
|
CVE-2002-0440
|
2008-09-11 04:12 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312532
|
10.0 |
HIGH
|
talentsoft
|
web\+_server
|
Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe.
|
NVD-CWE-Other
|
CVE-2002-0450
|
2008-09-11 04:12 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312533
|
5.1 |
MEDIUM
|
novell
|
web_search
|
Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter.
|
NVD-CWE-Other
|
CVE-2002-0530
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312534
|
7.5 |
HIGH
|
kth luke_mewburn
|
kth_kerberos lukemftp
|
Heap overflow in the KTH Kerberos 4 FTP client 4-1.1.1 allows remote malicious servers to execute arbitrary code on the client via a long response to a passive (PASV) mode request.
|
NVD-CWE-Other
|
CVE-2002-0600
|
2008-09-11 04:12 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312535
|
7.2 |
HIGH
|
sgi
|
irix
|
Unknown vulnerability in nveventd in NetVisualyzer on SGI IRIX 6.5 through 6.5.16 allows local users to write arbitrary files and gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-0631
|
2008-09-11 04:12 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312536
|
5.0 |
MEDIUM
|
sgi
|
irix
|
Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server.
|
NVD-CWE-Other
|
CVE-2002-0632
|
2008-09-11 04:12 |
2002-09-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312537
|
7.5 |
HIGH
|
openssl oracle apple
|
openssl application_server corporate_time_outlook_connector http_server mac_os_x
|
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and p…
|
NVD-CWE-Other
|
CVE-2002-0655
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312538
|
7.5 |
HIGH
|
openssl oracle apple
|
openssl application_server corporate_time_outlook_connector http_server mac_os_x
|
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SS…
|
NVD-CWE-Other
|
CVE-2002-0656
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312539
|
7.5 |
HIGH
|
openssl
|
openssl
|
Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key.
|
NVD-CWE-Other
|
CVE-2002-0657
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312540
|
5.0 |
MEDIUM
|
openssl oracle apple
|
openssl application_server corporate_time_outlook_connector http_server mac_os_x
|
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
|
NVD-CWE-Other
|
CVE-2002-0659
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312541
|
7.5 |
HIGH
|
symantec
|
norton_internet_security norton_personal_firewall
|
Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbit…
|
NVD-CWE-Other
|
CVE-2002-0663
|
2008-09-11 04:12 |
2002-07-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312542
|
5.0 |
MEDIUM
|
frees_wan apple freebsd netbsd global_technology_associates nec
|
frees_wan mac_os_x mac_os_x_server freebsd netbsd gnat_box_firmware bluefire_ix1035_router ix1010 ix1011 ix1020 ix1050 ix2010
|
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via s…
|
NVD-CWE-Other
|
CVE-2002-0666
|
2008-09-11 04:12 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312543
|
10.0 |
HIGH
|
pingtel
|
xpressa
|
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.
|
NVD-CWE-Other
|
CVE-2002-0667
|
2008-09-11 04:12 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312544
|
4.6 |
MEDIUM
|
pingtel
|
xpressa
|
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone.
|
NVD-CWE-Other
|
CVE-2002-0675
|
2008-09-11 04:12 |
2002-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312545
|
7.5 |
HIGH
|
suse
|
suse_linux
|
ifup-dhcp script in the sysconfig package for SuSE 8.0 allows remote attackers to execute arbitrary commands via spoofed DHCP responses, which are stored and executed in a file.
|
NVD-CWE-Other
|
CVE-2002-0758
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312546
|
7.2 |
HIGH
|
suse
|
suse_linux
|
shadow package in SuSE 8.0 allows local users to destroy the /etc/passwd and /etc/shadow files or assign extra group privileges to some users by changing filesize limits before calling programs that …
|
NVD-CWE-Other
|
CVE-2002-0762
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312547
|
7.5 |
HIGH
|
openbsd
|
openssh openbsd
|
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password.
|
NVD-CWE-Other
|
CVE-2002-0765
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312548
|
7.2 |
HIGH
|
openbsd
|
openbsd
|
OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1,…
|
NVD-CWE-Other
|
CVE-2002-0766
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312549
|
2.1 |
LOW
|
ibm
|
aix
|
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0790
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312550
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.
|
NVD-CWE-Other
|
CVE-2002-0803
|
2008-09-11 04:12 |
2002-08-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|