Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 305 763

Количество 305 763

nvd логотип

CVE-2002-1359

больше 22 лет назад

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2002-1358

больше 22 лет назад

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1357

больше 22 лет назад

Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-1356

больше 22 лет назад

Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1355

больше 22 лет назад

Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1354

больше 22 лет назад

Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1353

около 23 лет назад

LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1352

почти 22 года назад

Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product prices by changing the price parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1351

больше 22 лет назад

Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1350

больше 22 лет назад

The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1349

больше 22 лет назад

Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1348

больше 22 лет назад

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1347

больше 22 лет назад

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2002-1345

больше 22 лет назад

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1344

больше 22 лет назад

Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1342

больше 22 лет назад

Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1341

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1340

больше 22 лет назад

The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1339

больше 22 лет назад

The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1338

больше 22 лет назад

The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1359

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
87%
Высокий
больше 22 лет назад
nvd логотип
CVE-2002-1358

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
4%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1357

Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
18%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1356

Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1355

Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1354

Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1353

LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.

CVSS2: 5
0%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1352

Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product prices by changing the price parameter.

CVSS2: 5
1%
Низкий
почти 22 года назад
nvd логотип
CVE-2002-1351

Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request.

CVSS2: 5
8%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1350

The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1349

Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1348

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1347

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

CVSS3: 9.8
10%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1345

Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1344

Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1342

Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1341

Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.

CVSS2: 6.8
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1340

The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception.

CVSS2: 5
14%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1339

The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.

CVSS2: 5
14%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1338

The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.

CVSS2: 5
24%
Средний
больше 22 лет назад

Уязвимостей на страницу