|
314351
|
5.0 |
MEDIUM
|
key_focus
|
kf_web_server
|
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.
|
NVD-CWE-Other
|
CVE-2002-1031
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314352
|
7.5 |
HIGH
|
key_focus
|
kf_web_server
|
Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.
|
NVD-CWE-Other
|
CVE-2002-1032
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314353
|
5.0 |
MEDIUM
|
sun
|
i-runbook
|
Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot variant) in the argument.
|
NVD-CWE-Other
|
CVE-2002-1033
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314354
|
10.0 |
HIGH
|
sun
|
i-runbook
|
none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument.
|
NVD-CWE-Other
|
CVE-2002-1034
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314355
|
5.0 |
MEDIUM
|
omnicron
|
omnihttpd
|
Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number.
|
NVD-CWE-Other
|
CVE-2002-1035
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314356
|
7.5 |
HIGH
|
zoltan_milosevic
|
fluid_dynamics_search_engine
|
Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.
|
NVD-CWE-Other
|
CVE-2002-1036
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314357
|
5.0 |
MEDIUM
|
ibm
|
aix
|
Unknown vulnerability in the WebSecure (DFSWeb) configuration utilities in AIX 4.x, possibly related to relative pathnames.
|
NVD-CWE-Other
|
CVE-2002-1040
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314358
|
5.0 |
MEDIUM
|
netscape sun
|
enterprise_server iplanet_web_server one_application_server one_web_server
|
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read a…
|
NVD-CWE-Other
|
CVE-2002-1042
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314359
|
5.0 |
MEDIUM
|
ultrafunk
|
popcorn
|
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").
|
NVD-CWE-Other
|
CVE-2002-1043
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314360
|
7.5 |
HIGH
|
ultrafunk
|
popcorn
|
Buffer overflow in Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Subject field.
|
NVD-CWE-Other
|
CVE-2002-1044
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314361
|
5.0 |
MEDIUM
|
ultrafunk
|
popcorn
|
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Date field that is converted into a year greater than 2037.
|
NVD-CWE-Other
|
CVE-2002-1045
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314362
|
5.0 |
MEDIUM
|
watchguard
|
firebox soho_firewall
|
Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to…
|
NVD-CWE-Other
|
CVE-2002-1046
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314363
|
7.5 |
HIGH
|
watchguard
|
soho_firewall
|
The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name.
|
NVD-CWE-Other
|
CVE-2002-1047
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314364
|
7.5 |
HIGH
|
hp
|
jetdirect
|
HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0.
|
NVD-CWE-Other
|
CVE-2002-1048
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314365
|
5.0 |
MEDIUM
|
hylafax
|
hylafax
|
Format string vulnerability in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service (crash) via the TSI data element.
|
NVD-CWE-Other
|
CVE-2002-1049
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314366
|
7.5 |
HIGH
|
hylafax
|
hylafax
|
Buffer overflow in HylaFAX faxgetty before 4.1.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long line of image data.
|
NVD-CWE-Other
|
CVE-2002-1050
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314367
|
6.8 |
MEDIUM
|
w3c
|
jigsaw
|
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed…
|
NVD-CWE-Other
|
CVE-2002-1053
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314368
|
5.0 |
MEDIUM
|
brother
|
nc-3100h
|
Buffer overflow in administrative web server for Brother NC-3100h printer allows remote attackers to cause a denial of service via a long password.
|
NVD-CWE-Other
|
CVE-2002-1055
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314369
|
7.5 |
HIGH
|
smartmax_software
|
mailmax
|
Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command.
|
NVD-CWE-Other
|
CVE-2002-1057
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314370
|
10.0 |
HIGH
|
cobalt
|
qube
|
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cook…
|
NVD-CWE-Other
|
CVE-2002-1058
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314371
|
4.3 |
MEDIUM
|
bluecoat
|
cacheos
|
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers…
|
NVD-CWE-Other
|
CVE-2002-1060
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314372
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP…
|
NVD-CWE-Other
|
CVE-2002-1061
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314373
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.
|
NVD-CWE-Other
|
CVE-2002-1062
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314374
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV requests, which consumes a…
|
NVD-CWE-Other
|
CVE-2002-1063
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314375
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
|
NVD-CWE-Other
|
CVE-2002-1064
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314376
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute…
|
NVD-CWE-Other
|
CVE-2002-1065
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314377
|
7.5 |
HIGH
|
t._hauck
|
jana_web_server
|
Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command t…
|
NVD-CWE-Other
|
CVE-2002-1066
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314378
|
5.0 |
MEDIUM
|
seh
|
ic9_pocket_print_server_firmware
|
Administrative web interface for IC9 Pocket Print Server Firmware 7.1.30 and 7.1.36f allows remote attackers to cause a denial of service (reboot and reset) via a long password, possibly due to a buf…
|
NVD-CWE-Other
|
CVE-2002-1067
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314379
|
7.5 |
HIGH
|
php-wiki
|
php-wiki
|
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.
|
NVD-CWE-Other
|
CVE-2002-1070
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314380
|
5.0 |
MEDIUM
|
zyxel
|
prestige
|
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.
|
NVD-CWE-Other
|
CVE-2002-1071
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314381
|
5.0 |
MEDIUM
|
zyxel
|
prestige
|
ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.
|
NVD-CWE-Other
|
CVE-2002-1072
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314382
|
7.5 |
HIGH
|
atrium_software
|
mercur_mailserver
|
Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.
|
NVD-CWE-Other
|
CVE-2002-1073
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314383
|
7.5 |
HIGH
|
david_harris
|
pegasus_mail
|
Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.
|
NVD-CWE-Other
|
CVE-2002-1075
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314384
|
7.5 |
HIGH
|
ipswitch
|
imail
|
Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.
|
NVD-CWE-Other
|
CVE-2002-1076
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314385
|
5.0 |
MEDIUM
|
ipswitch
|
imail
|
IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.
|
NVD-CWE-Other
|
CVE-2002-1077
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314386
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters.
|
NVD-CWE-Other
|
CVE-2002-1078
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314387
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2002-1079
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314388
|
7.5 |
HIGH
|
aprelium_technologies
|
abyss_web_server
|
The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.…
|
NVD-CWE-Other
|
CVE-2002-1080
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314389
|
5.0 |
MEDIUM
|
aprelium_technologies
|
abyss_web_server
|
The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.
|
NVD-CWE-Other
|
CVE-2002-1081
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314390
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.
|
NVD-CWE-Other
|
CVE-2002-1082
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314391
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or …
|
NVD-CWE-Other
|
CVE-2002-1083
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314392
|
6.4 |
MEDIUM
|
visualshapers
|
ezcontents
|
The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted inform…
|
NVD-CWE-Other
|
CVE-2002-1084
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314393
|
7.5 |
HIGH
|
visualshapers
|
ezcontents
|
Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.
|
NVD-CWE-Other
|
CVE-2002-1085
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314394
|
7.5 |
HIGH
|
visualshapers
|
ezcontents
|
Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.
|
NVD-CWE-Other
|
CVE-2002-1086
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314395
|
5.0 |
MEDIUM
|
visualshapers
|
ezcontents
|
The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upl…
|
NVD-CWE-Other
|
CVE-2002-1087
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314396
|
7.5 |
HIGH
|
novell
|
groupwise
|
Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
|
NVD-CWE-Other
|
CVE-2002-1088
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314397
|
5.0 |
MEDIUM
|
oracle
|
application_server reports
|
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
|
NVD-CWE-Other
|
CVE-2002-1089
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314398
|
7.5 |
HIGH
|
libesmtp
|
libesmtp
|
Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via lon…
|
NVD-CWE-Other
|
CVE-2002-1090
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314399
|
7.2 |
HIGH
|
purity
|
purity
|
Multiple buffer overflows in purity 1-16 allow local users to gain privileges and modify high scores tables.
|
NVD-CWE-Other
|
CVE-2002-1124
|
2008-09-6 05:29 |
2002-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314400
|
7.2 |
HIGH
|
digital
|
osf_1
|
Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.
|
NVD-CWE-Other
|
CVE-2002-1127
|
2008-09-6 05:29 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|