Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 024

Количество 307 024

nvd логотип

CVE-2002-2000

больше 22 лет назад

ACMS 4.3 and 4.4 in OpenVMS Alpha 7.2 and 7.3 does not properly use process privileges, which allows attackers to access data.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-20002

8 месяцев назад

The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2002-20001

почти 4 года назад

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1999

больше 22 лет назад

HP Praesidium Webproxy 1.0 running on HP-UX 11.04 VVOS could allow remote attackers to cause Webproxy to forward requests to the internal network via crafted HTTP requests.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1998

больше 22 лет назад

Buffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to execute arbitrary commands via a long parameter to rtable_create (procedure 21).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1997

больше 22 лет назад

ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1996

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2002-1995

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1994

больше 22 лет назад

advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1993

больше 22 лет назад

webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1992

больше 22 лет назад

Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1991

больше 22 лет назад

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1990

больше 22 лет назад

Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1989

больше 22 лет назад

Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1988

больше 22 лет назад

Resin 2.1.1 allows remote attackers to cause a denial of service (memory consumption and hang) via a URL with long variables for non-existent resources.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1987

больше 22 лет назад

Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1986

больше 22 лет назад

Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1985

больше 22 лет назад

iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long "MAIL FROM" command, possibly triggering a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1984

больше 22 лет назад

Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1983

больше 22 лет назад

The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-2000

ACMS 4.3 and 4.4 in OpenVMS Alpha 7.2 and 7.3 does not properly use process privileges, which allows attackers to access data.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-20002

The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2002-20001

The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE.

CVSS3: 7.5
12%
Средний
почти 4 года назад
nvd логотип
CVE-2002-1999

HP Praesidium Webproxy 1.0 running on HP-UX 11.04 VVOS could allow remote attackers to cause Webproxy to forward requests to the internal network via crafted HTTP requests.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1998

Buffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to execute arbitrary commands via a long parameter to rtable_create (procedure 21).

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1997

ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1996

Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.

CVSS2: 2.6
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1995

Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn parameter.

CVSS2: 4.3
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1994

advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1993

webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.

CVSS2: 10
7%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1992

Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.

CVSS2: 5
6%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1991

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

CVSS2: 7.5
5%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1990

Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1989

Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1988

Resin 2.1.1 allows remote attackers to cause a denial of service (memory consumption and hang) via a URL with long variables for non-existent resources.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1987

Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1986

Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").

CVSS2: 5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1985

iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long "MAIL FROM" command, possibly triggering a buffer overflow.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1984

Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".

CVSS2: 5
12%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1983

The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад

Уязвимостей на страницу