|
362851
|
5.0 |
MEDIUM
|
teekai
|
teekai_forum
|
TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to id…
|
NVD-CWE-Other
|
CVE-2002-2057
|
2016-10-18 11:27 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362852
|
4.3 |
MEDIUM
|
microsoft
|
site_server site_server_commerce windows_nt
|
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr paramet…
|
NVD-CWE-Other
|
CVE-2002-2073
|
2016-10-18 11:27 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362853
|
5.0 |
MEDIUM
|
blue_world_communications
|
lasso_web_data_engine
|
Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL.
|
NVD-CWE-Other
|
CVE-2002-2118
|
2016-10-18 11:27 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362854
|
5.0 |
MEDIUM
|
surfcontrol
|
superscout_email_filter
|
SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a buffer overflow.
|
NVD-CWE-Other
|
CVE-2002-2121
|
2016-10-18 11:27 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362855
|
4.0 |
MEDIUM
|
php
|
phpsquidpass
|
phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a shor…
|
NVD-CWE-Other
|
CVE-2002-2175
|
2016-10-18 11:27 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362856
|
4.0 |
MEDIUM
|
php
|
phpsquidpass
|
This vulnerability affects all versions of phpSquidPass before 0.2
|
NVD-CWE-Other
|
CVE-2002-2175
|
2016-10-18 11:27 |
2002-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362857
|
5.0 |
MEDIUM
|
microsoft
|
office_web_components
|
The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions,…
|
NVD-CWE-Other
|
CVE-2002-1339
|
2016-10-18 11:26 |
2002-12-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362858
|
5.0 |
MEDIUM
|
microsoft
|
office_web_components
|
The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception.
|
NVD-CWE-Other
|
CVE-2002-1340
|
2016-10-18 11:26 |
2002-12-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362859
|
5.0 |
MEDIUM
|
w3m
|
w3m
|
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
|
NVD-CWE-Other
|
CVE-2002-1348
|
2016-10-18 11:26 |
2003-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362860
|
10.0 |
HIGH
|
easy_software_products apple
|
cups mac_os_x
|
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-co…
|
NVD-CWE-Other
|
CVE-2002-1383
|
2016-10-18 11:26 |
2002-12-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362861
|
4.6 |
MEDIUM
|
ehud_gavron
|
tracesroute
|
Buffer overflow in traceroute-nanog (aka traceroute-ng) may allow local users to execute arbitrary code via a long hostname argument.
|
NVD-CWE-Other
|
CVE-2002-1386
|
2016-10-18 11:26 |
2003-01-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362862
|
4.6 |
MEDIUM
|
ehud_gavron
|
tracesroute
|
The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via an array index overflow using the nprobes (number of probes) argument.
|
NVD-CWE-Other
|
CVE-2002-1387
|
2016-10-18 11:26 |
2003-01-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362863
|
7.5 |
HIGH
|
kde
|
kde
|
Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands vi…
|
NVD-CWE-Other
|
CVE-2002-1393
|
2016-10-18 11:26 |
2003-01-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362864
|
4.6 |
MEDIUM
|
postgresql
|
postgresql
|
Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handli…
|
NVD-CWE-Other
|
CVE-2002-1398
|
2016-10-18 11:26 |
2003-01-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362865
|
10.0 |
HIGH
|
postgresql
|
postgresql
|
Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which …
|
NVD-CWE-Other
|
CVE-2002-1399
|
2016-10-18 11:26 |
2003-01-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362866
|
7.5 |
HIGH
|
postgresql
|
postgresql
|
Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string.
|
NVD-CWE-Other
|
CVE-2002-1400
|
2016-10-18 11:26 |
2003-01-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362867
|
4.6 |
MEDIUM
|
postgresql
|
postgresql
|
Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2002-1402
|
2016-10-18 11:26 |
2003-01-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362868
|
5.0 |
MEDIUM
|
elinks links university_of_kansas
|
elinks links lynx
|
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded car…
|
NVD-CWE-Other
|
CVE-2002-1405
|
2016-10-18 11:26 |
2003-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362869
|
4.6 |
MEDIUM
|
inter7
|
qmailadmin
|
Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable.
|
NVD-CWE-Other
|
CVE-2002-1414
|
2016-10-18 11:26 |
2003-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362870
|
5.0 |
MEDIUM
|
debian hp redhat
|
debian_linux secure_os linux
|
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests f…
|
NVD-CWE-Other
|
CVE-2002-1232
|
2016-10-18 11:25 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362871
|
2.6 |
LOW
|
apache
|
http_server
|
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or mo…
|
NVD-CWE-Other
|
CVE-2002-1233
|
2016-10-18 11:25 |
2002-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362872
|
5.0 |
MEDIUM
|
linksys
|
befsr41
|
The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi w…
|
NVD-CWE-Other
|
CVE-2002-1236
|
2016-10-18 11:25 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362873
|
7.2 |
HIGH
|
qnx
|
rtos
|
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH t…
|
NVD-CWE-Other
|
CVE-2002-1239
|
2016-10-18 11:25 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362874
|
7.5 |
HIGH
|
francisco_burzi
|
php-nuke
|
SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.
|
NVD-CWE-Other
|
CVE-2002-1242
|
2016-10-18 11:25 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362875
|
7.5 |
HIGH
|
pablo_software_solutions
|
pablo_ftp_server
|
Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in t…
|
NVD-CWE-Other
|
CVE-2002-1244
|
2016-10-18 11:25 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362876
|
7.2 |
HIGH
|
frank_mcingvale
|
luxman
|
Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable …
|
NVD-CWE-Other
|
CVE-2002-1245
|
2016-10-18 11:25 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362877
|
7.2 |
HIGH
|
kde lisa
|
klisa lisa kde
|
Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon.
|
NVD-CWE-Other
|
CVE-2002-1247
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362878
|
5.0 |
MEDIUM
|
northern_solutions
|
xeneo_web_server
|
Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) via a GET request for a "%" URI.
|
NVD-CWE-Other
|
CVE-2002-1248
|
2016-10-18 11:25 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362879
|
7.5 |
HIGH
|
oracle
|
oracle9i
|
Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.
|
NVD-CWE-Other
|
CVE-2002-1264
|
2016-10-18 11:25 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362880
|
7.5 |
HIGH
|
perl-mailtools
|
perl-mailtools
|
The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the ma…
|
NVD-CWE-Other
|
CVE-2002-1271
|
2016-10-18 11:25 |
2002-11-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362881
|
7.5 |
HIGH
|
kde
|
kde
|
Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote attackers to execute arbitrary code via a certain …
|
NVD-CWE-Other
|
CVE-2002-1281
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362882
|
7.5 |
HIGH
|
kde
|
kde
|
Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL.
|
NVD-CWE-Other
|
CVE-2002-1282
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362883
|
5.0 |
MEDIUM
|
microsoft
|
java_virtual_machine
|
Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or…
|
NVD-CWE-Other
|
CVE-2002-1287
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362884
|
5.0 |
MEDIUM
|
microsoft
|
java_virtual_machine
|
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File…
|
NVD-CWE-Other
|
CVE-2002-1288
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362885
|
7.5 |
HIGH
|
microsoft
|
java_virtual_machine
|
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via …
|
NVD-CWE-Other
|
CVE-2002-1289
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362886
|
6.4 |
MEDIUM
|
microsoft
|
java_virtual_machine
|
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) …
|
NVD-CWE-Other
|
CVE-2002-1290
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362887
|
5.0 |
MEDIUM
|
microsoft
|
java_virtual_machine
|
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null…
|
NVD-CWE-Other
|
CVE-2002-1291
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362888
|
7.5 |
HIGH
|
microsoft
|
java_virtual_machine
|
The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the s…
|
NVD-CWE-Other
|
CVE-2002-1293
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362889
|
7.5 |
HIGH
|
microsoft
|
java_virtual_machine
|
The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to…
|
NVD-CWE-Other
|
CVE-2002-1294
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362890
|
7.5 |
HIGH
|
kde
|
kde
|
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote…
|
NVD-CWE-Other
|
CVE-2002-1306
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362891
|
7.5 |
HIGH
|
macromedia
|
coldfusion
|
Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary via an HTTP GET request with a long .cfm…
|
NVD-CWE-Other
|
CVE-2002-1309
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362892
|
4.6 |
MEDIUM
|
double_precision_incorporated
|
courier_mta
|
Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2002-1311
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362893
|
6.8 |
MEDIUM
|
iplanet
|
iplanet_web_server
|
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the…
|
NVD-CWE-Other
|
CVE-2002-1315
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362894
|
6.8 |
MEDIUM
|
iplanet
|
iplanet_web_server
|
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows rem…
|
NVD-CWE-Other
|
CVE-2002-1316
|
2016-10-18 11:25 |
2002-11-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362895
|
5.0 |
MEDIUM
|
university_of_washington
|
pine
|
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From header that contains a large number of quotation marks (").
|
NVD-CWE-Other
|
CVE-2002-1320
|
2016-10-18 11:25 |
2002-12-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362896
|
7.5 |
HIGH
|
phpwebsite
|
phpwebsite
|
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code.
|
NVD-CWE-Other
|
CVE-2002-1135
|
2016-10-18 11:24 |
2002-10-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362897
|
7.1 |
HIGH
|
hp
|
procurve_switch_4000m
|
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, w…
|
NVD-CWE-Other
|
CVE-2002-1147
|
2016-10-18 11:24 |
2002-10-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362898
|
7.1 |
HIGH
|
hp
|
procurve_switch_4000m
|
Successful exploitation requires that stacking features and remote administration are enabled.
|
NVD-CWE-Other
|
CVE-2002-1147
|
2016-10-18 11:24 |
2002-10-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362899
|
5.0 |
MEDIUM
|
invision_power_services
|
invision_board
|
The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and…
|
NVD-CWE-Other
|
CVE-2002-1149
|
2016-10-18 11:24 |
2002-10-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362900
|
4.6 |
MEDIUM
|
microsoft
|
netmeeting
|
The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering ce…
|
NVD-CWE-Other
|
CVE-2002-1150
|
2016-10-18 11:24 |
2002-10-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|