|
363051
|
5.4 |
MEDIUM
|
realnetworks
|
realplayer
|
RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files.
|
NVD-CWE-Other
|
CVE-2002-0337
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363052
|
5.0 |
MEDIUM
|
ritlabs
|
the_bat
|
The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.
|
NVD-CWE-Other
|
CVE-2002-0338
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363053
|
7.5 |
HIGH
|
microsoft
|
windows_media_player
|
Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, …
|
NVD-CWE-Other
|
CVE-2002-0340
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363054
|
5.0 |
MEDIUM
|
novell
|
groupwise
|
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.
|
NVD-CWE-Other
|
CVE-2002-0341
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363055
|
5.0 |
MEDIUM
|
kde
|
k-mail
|
Kmail 1.2 on KDE 2.1.1 allows remote attackers to cause a denial of service (crash) via an email message whose body is approximately 55 K long.
|
NVD-CWE-Other
|
CVE-2002-0342
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363056
|
4.6 |
MEDIUM
|
hotline_communications
|
hotline_connect
|
Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by …
|
NVD-CWE-Other
|
CVE-2002-0343
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363057
|
5.0 |
MEDIUM
|
symantec
|
liveupdate
|
Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the …
|
NVD-CWE-Other
|
CVE-2002-0344
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363058
|
7.5 |
HIGH
|
symantec
|
norton_ghost
|
Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0345
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363059
|
7.5 |
HIGH
|
sun
|
cobalt_raq_2 cobalt_raq_3i cobalt_raq_4
|
Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.
|
NVD-CWE-Other
|
CVE-2002-0346
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363060
|
5.0 |
MEDIUM
|
sun
|
cobalt_raq_2 cobalt_raq_3i cobalt_raq_4
|
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0347
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363061
|
7.5 |
HIGH
|
sun
|
cobalt_raq_2 cobalt_raq_3i cobalt_raq_4
|
service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.
|
NVD-CWE-Other
|
CVE-2002-0348
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363062
|
4.6 |
MEDIUM
|
tiny_software
|
tiny_personal_firewall
|
Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine…
|
NVD-CWE-Other
|
CVE-2002-0349
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363063
|
7.8 |
HIGH
|
hp
|
procurve_switch_4000m
|
HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service.
|
NVD-CWE-Other
|
CVE-2002-0350
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363064
|
5.0 |
MEDIUM
|
phorum
|
phorum
|
Phorum 3.3.2 allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the stats.php program, which does not require authentication.
|
NVD-CWE-Other
|
CVE-2002-0352
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363065
|
5.0 |
MEDIUM
|
mozilla netscape
|
mozilla navigator
|
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the brows…
|
NVD-CWE-Other
|
CVE-2002-0354
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363066
|
10.0 |
HIGH
|
sgi
|
irix
|
xfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can mount or unmount xfs file systems, to gain root pri…
|
NVD-CWE-Other
|
CVE-2002-0359
|
2016-10-18 11:19 |
2002-07-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363067
|
7.5 |
HIGH
|
sun
|
solaris_answerbook2
|
Buffer overflow in Sun AnswerBook2 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long filename argument to the gettransbitmap CGI program.
|
NVD-CWE-Other
|
CVE-2002-0360
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363068
|
7.5 |
HIGH
|
aol
|
instant_messenger
|
Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and a TLV type greater than 0x2711.
|
NVD-CWE-Other
|
CVE-2002-0362
|
2016-10-18 11:19 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363069
|
7.5 |
HIGH
|
padl_software
|
pam_ldap
|
Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name.
|
NVD-CWE-Other
|
CVE-2002-0374
|
2016-10-18 11:19 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363070
|
2.1 |
LOW
|
rob_flynn
|
gaim
|
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by readi…
|
NVD-CWE-Other
|
CVE-2002-0377
|
2016-10-18 11:19 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363071
|
7.5 |
HIGH
|
lbl
|
tcpdump
|
Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS packet.
|
NVD-CWE-Other
|
CVE-2002-0380
|
2016-10-18 11:19 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363072
|
7.5 |
HIGH
|
xchat
|
xchat
|
XChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell metacharacters.
|
NVD-CWE-Other
|
CVE-2002-0382
|
2016-10-18 11:19 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363073
|
4.3 |
MEDIUM
|
opera_software
|
opera_web_browser
|
Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attac…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2002-0270
|
2016-10-18 11:18 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363074
|
1.2 |
LOW
|
ada_core_technologies
|
gnat_pro_native
|
Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2002-0271
|
2016-10-18 11:18 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363075
|
10.0 |
HIGH
|
mpg321
|
mpg321
|
Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.
|
NVD-CWE-Other
|
CVE-2002-0272
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363076
|
4.6 |
MEDIUM
|
netwin
|
cwmail
|
Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter.
|
NVD-CWE-Other
|
CVE-2002-0273
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363077
|
4.6 |
MEDIUM
|
university_of_cambridge
|
exim
|
Exim 3.34 and earlier may allow local users to gain privileges via a buffer overflow in long -C (configuration file) and other command line arguments.
|
NVD-CWE-Other
|
CVE-2002-0274
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363078
|
7.5 |
HIGH
|
ettercap
|
ettercap
|
Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2000, allows remote attackers to execute arbitrary code via large packets.
|
NVD-CWE-Other
|
CVE-2002-0276
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363079
|
7.5 |
HIGH
|
add2it
|
mailman_free
|
Add2it Mailman Free 1.73 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the list parameter.
|
NVD-CWE-Other
|
CVE-2002-0277
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363080
|
7.5 |
HIGH
|
add2it
|
mailman_free
|
Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.
|
NVD-CWE-Other
|
CVE-2002-0278
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363081
|
7.5 |
HIGH
|
codeblue
|
codeblue
|
Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply.
|
NVD-CWE-Other
|
CVE-2002-0280
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363082
|
5.0 |
MEDIUM
|
microsoft
|
windows_xp
|
Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data.
|
NVD-CWE-Other
|
CVE-2002-0283
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363083
|
2.6 |
LOW
|
nullsoft
|
winamp
|
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow …
|
NVD-CWE-Other
|
CVE-2002-0284
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363084
|
7.5 |
HIGH
|
microsoft
|
outlook_express
|
Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to b…
|
NVD-CWE-Other
|
CVE-2002-0285
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363085
|
10.0 |
HIGH
|
powie
|
pforum
|
pforum 1.14 and earlier does not explicitly enable PHP magic quotes, which allows remote attackers to bypass authentication and gain administrator privileges via an SQL injection attack when the PHP …
|
NVD-CWE-Other
|
CVE-2002-0287
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363086
|
5.0 |
MEDIUM
|
bbshareware.com
|
phusion_webserver
|
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0288
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363087
|
5.0 |
MEDIUM
|
bbshareware.com
|
phusion_webserver
|
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0289
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363088
|
7.5 |
HIGH
|
netwin
|
webnews
|
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.
|
NVD-CWE-Other
|
CVE-2002-0290
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363089
|
5.0 |
MEDIUM
|
funsoft
|
dinos_webserver
|
Dino's Webserver 1.2 allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via several large HTTP requests within a short time.
|
NVD-CWE-Other
|
CVE-2002-0291
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363090
|
2.6 |
LOW
|
open_source_development_network
|
slashcode
|
Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript i…
|
NVD-CWE-Other
|
CVE-2002-0292
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363091
|
2.1 |
LOW
|
alcatel-lucent
|
omnipcx
|
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.
|
NVD-CWE-Other
|
CVE-2002-0294
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363092
|
4.6 |
MEDIUM
|
alcatel-lucent
|
omnipcx
|
Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0295
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363093
|
5.0 |
MEDIUM
|
nombas
|
scriptease_webserver
|
Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0297
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363094
|
5.0 |
MEDIUM
|
nombas
|
scriptease_webserver
|
ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequenc…
|
NVD-CWE-Other
|
CVE-2002-0298
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363095
|
7.6 |
HIGH
|
cnet
|
catchup
|
CNet CatchUp before 1.3.1 allows attackers to execute arbitrary code via a .RVP file that creates a file with an arbitrary extension (such as .BAT), which is executed during a scan.
|
NVD-CWE-Other
|
CVE-2002-0299
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363096
|
5.0 |
MEDIUM
|
gnujsp
|
gnujsp
|
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet,…
|
NVD-CWE-Other
|
CVE-2002-0300
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363097
|
5.0 |
MEDIUM
|
citrix
|
nfuse
|
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.
|
NVD-CWE-Other
|
CVE-2002-0301
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363098
|
4.6 |
MEDIUM
|
novell
|
groupwise
|
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.
|
NVD-CWE-Other
|
CVE-2002-0303
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363099
|
5.0 |
MEDIUM
|
summit_computer_networks
|
lil_http_server
|
Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0304
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363100
|
7.5 |
HIGH
|
avengers_news_system
|
avengers_news_system
|
ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.
|
NVD-CWE-Other
|
CVE-2002-0306
|
2016-10-18 11:18 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|