|
352251
|
5.0 |
MEDIUM
|
cerulean_studios
|
trillian
|
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, …
|
NVD-CWE-Other
|
CVE-2002-1487
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352252
|
5.0 |
MEDIUM
|
cerulean_studios
|
trillian
|
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian u…
|
NVD-CWE-Other
|
CVE-2002-1488
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352253
|
7.5 |
HIGH
|
planetdns
|
planetweb
|
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.
|
NVD-CWE-Other
|
CVE-2002-1489
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352254
|
2.1 |
LOW
|
netbsd
|
netbsd
|
NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the TIOCSCTTY ioctl, which causes an integer overflow in a structure counter and se…
|
NVD-CWE-Other
|
CVE-2002-1490
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352255
|
5.0 |
MEDIUM
|
cisco
|
vpn_5000_client
|
The Cisco VPN 5000 Client for MacOS before 5.2.2 records the most recently used login password in plaintext when saving "Default Connection" settings, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-1491
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352256
|
7.2 |
HIGH
|
cisco
|
vpn_5000_client
|
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.
|
NVD-CWE-Other
|
CVE-2002-1492
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352257
|
4.3 |
MEDIUM
|
aestiva
|
html_os
|
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script…
|
NVD-CWE-Other
|
CVE-2002-1494
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352258
|
4.3 |
MEDIUM
|
rudi_benkovic
|
jawmail
|
Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that a…
|
NVD-CWE-Other
|
CVE-2002-1495
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352259
|
7.5 |
HIGH
|
nulllogic
|
null_httpd
|
Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header.
|
NVD-CWE-Other
|
CVE-2002-1496
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352260
|
5.0 |
MEDIUM
|
trevor_lee
|
swserver
|
Directory traversal vulnerability in SWServer 2.2 and earlier allows remote attackers to read arbitrary files via a URL containing .. sequences with "/" or "\" characters.
|
NVD-CWE-Other
|
CVE-2002-1498
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352261
|
7.5 |
HIGH
|
factosystem
|
factosystem_weblog
|
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid par…
|
NVD-CWE-Other
|
CVE-2002-1499
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352262
|
7.2 |
HIGH
|
netbsd
|
netbsd
|
Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which pro…
|
NVD-CWE-Other
|
CVE-2002-1500
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352263
|
5.0 |
MEDIUM
|
enterasys
|
smartswitch_ssr8000
|
The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078.
|
NVD-CWE-Other
|
CVE-2002-1501
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352264
|
2.1 |
LOW
|
dave_brul
|
xbreaky
|
Symbolic link vulnerability in xbreaky before 0.5.5 allows local users to overwrite arbitrary files via a symlink from the user's .breakyhighscores file to the target file.
|
NVD-CWE-Other
|
CVE-2002-1502
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352265
|
7.2 |
HIGH
|
afd
|
afd
|
Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR environment variable or -w (workdir) argument to (1) afd, (2) afdc…
|
NVD-CWE-Other
|
CVE-2002-1503
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352266
|
5.0 |
MEDIUM
|
radiobird_software
|
webserver_4_everyone
|
Directory traversal vulnerability in WebServer 4 Everyone 1.22 allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a URL.
|
NVD-CWE-Other
|
CVE-2002-1504
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352267
|
7.5 |
HIGH
|
woltlab
|
burning_board
|
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.
|
NVD-CWE-Other
|
CVE-2002-1505
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352268
|
7.2 |
HIGH
|
jacques_gelinas
|
linuxconf
|
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable, which overflows an error string that is generated.
|
NVD-CWE-Other
|
CVE-2002-1506
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352269
|
5.0 |
MEDIUM
|
epic_games
|
unreal_tournament_server
|
Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports 7778 or 10777.
|
NVD-CWE-Other
|
CVE-2002-1507
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352270
|
10.0 |
HIGH
|
xfree86_project
|
x11r6
|
xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.
|
NVD-CWE-Other
|
CVE-2002-1510
|
2008-09-6 05:30 |
2003-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352271
|
6.2 |
MEDIUM
|
tolis_group
|
bru
|
xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file.
|
NVD-CWE-Other
|
CVE-2002-1512
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352272
|
4.6 |
MEDIUM
|
compaq
|
tcp-ip_services
|
The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions becau…
|
NVD-CWE-Other
|
CVE-2002-1513
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352273
|
7.2 |
HIGH
|
borland_software
|
interbase
|
gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.
|
NVD-CWE-Other
|
CVE-2002-1514
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352274
|
5.0 |
MEDIUM
|
coolforum
|
coolforum
|
Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter.
|
NVD-CWE-Other
|
CVE-2002-1515
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352275
|
4.6 |
MEDIUM
|
sgi
|
freeware irix
|
fsr_efs in IRIX 6.5 allows local users to conduct unauthorized file activities via a symlink attack, possibly via the .fsrlast file.
|
NVD-CWE-Other
|
CVE-2002-1517
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352276
|
3.6 |
LOW
|
sgi
|
irix
|
mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local users to modify files and directories.
|
NVD-CWE-Other
|
CVE-2002-1518
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352277
|
10.0 |
HIGH
|
rapidstream watchguard
|
rapidstream firebox
|
Format string vulnerability in the CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, allows remote attackers to cause a denial of service and possibly execute arb…
|
NVD-CWE-Other
|
CVE-2002-1519
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352278
|
10.0 |
HIGH
|
rapidstream watchguard
|
rapidstream firebox
|
The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows …
|
NVD-CWE-Other
|
CVE-2002-1520
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352279
|
2.1 |
LOW
|
mdg_computer_services
|
web_server_4d
|
Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-1521
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352280
|
5.0 |
MEDIUM
|
cooolsoft
|
powerftp
|
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.
|
NVD-CWE-Other
|
CVE-2002-1522
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352281
|
5.0 |
MEDIUM
|
daniel_arenz
|
mini_server
|
Directory traversal vulnerability in Daniel Arenz Mini Server 2.1.6 allows remote attackers to read arbitrary files via (1) ../ (dot-dot slash) or (2) ..\ (dot-dot backslash) sequences.
|
NVD-CWE-Other
|
CVE-2002-1523
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352282
|
7.5 |
HIGH
|
nullsoft
|
winamp
|
Buffer overflow in XML parser in wsabi.dll of Winamp 3 (1.0.0.488) allows remote attackers to execute arbitrary code via a skin file (.wal) with a long include file tag.
|
NVD-CWE-Other
|
CVE-2002-1524
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352283
|
5.0 |
MEDIUM
|
astaware sun
|
searchdisc sunone_starter_kit
|
Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or …
|
NVD-CWE-Other
|
CVE-2002-1525
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352284
|
4.3 |
MEDIUM
|
emumail
|
emu_webmail
|
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field.
|
NVD-CWE-Other
|
CVE-2002-1526
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352285
|
5.0 |
MEDIUM
|
emumail
|
emu_webmail
|
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error tha…
|
NVD-CWE-Other
|
CVE-2002-1527
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352286
|
5.0 |
MEDIUM
|
mondosoft
|
mondosearch
|
MsmMask.exe in MondoSearch 4.4 allows remote attackers to obtain the source code of scripts via the mask parameter.
|
NVD-CWE-Other
|
CVE-2002-1528
|
2008-09-6 05:30 |
2003-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352287
|
4.3 |
MEDIUM
|
surfcontrol
|
superscout_email_filter
|
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or …
|
NVD-CWE-Other
|
CVE-2002-1529
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352288
|
5.0 |
MEDIUM
|
surfcontrol
|
superscout_email_filter
|
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes …
|
NVD-CWE-Other
|
CVE-2002-1530
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352289
|
5.0 |
MEDIUM
|
surfcontrol
|
superscout_email_filter
|
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter.
|
NVD-CWE-Other
|
CVE-2002-1531
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352290
|
5.0 |
MEDIUM
|
surfcontrol
|
superscout_email_filter
|
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminatin…
|
NVD-CWE-Other
|
CVE-2002-1532
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352291
|
5.8 |
MEDIUM
|
jetty
|
jetty
|
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious sc…
|
NVD-CWE-Other
|
CVE-2002-1533
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352292
|
5.0 |
MEDIUM
|
macromedia
|
flash_player
|
Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share.
|
NVD-CWE-Other
|
CVE-2002-1534
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352293
|
5.0 |
MEDIUM
|
symantec
|
enterprise_firewall raptor_firewall
|
Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates diff…
|
NVD-CWE-Other
|
CVE-2002-1535
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352294
|
7.5 |
HIGH
|
hans_persson
|
molly
|
Molly IRC bot 0.5 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $host variable for nslookup.pl, (2) the $to, $from, or $message variables in pop.pl, (3) th…
|
NVD-CWE-Other
|
CVE-2002-1536
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352295
|
10.0 |
HIGH
|
phpbb_group
|
phpbb
|
admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".
|
NVD-CWE-Other
|
CVE-2002-1537
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352296
|
5.0 |
MEDIUM
|
acuma
|
acusend
|
Acuma Acusend 4, and possibly earlier versions, allows remote authenticated users to read the reports of other users by inferring the full URL, whose name is easily predictable.
|
NVD-CWE-Other
|
CVE-2002-1538
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352297
|
5.0 |
MEDIUM
|
alt-n
|
mdaemon
|
Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.
|
NVD-CWE-Other
|
CVE-2002-1539
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352298
|
7.5 |
HIGH
|
working_resources_inc.
|
badblue
|
BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).
|
NVD-CWE-Other
|
CVE-2002-1541
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352299
|
5.0 |
MEDIUM
|
solarwinds
|
tftp_server
|
SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-1542
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352300
|
4.6 |
MEDIUM
|
netbsd
|
netbsd
|
Buffer overflow in trek on NetBSD 1.5 through 1.5.3 allows local users to gain privileges via long keyboard input.
|
NVD-CWE-Other
|
CVE-2002-1543
|
2008-09-6 05:30 |
2003-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|