Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 152

Количество 307 152

nvd логотип

CVE-2002-1229

почти 23 года назад

Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1228

почти 23 года назад

Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1227

почти 23 года назад

PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1226

почти 23 года назад

Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1225

почти 23 года назад

Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1224

почти 23 года назад

Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1223

почти 23 года назад

Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a denial of service or execute arbitrary code via a modified .ps (PostScript) input file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1222

почти 23 года назад

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

CVSS2: 7.1
EPSS: Средний
nvd логотип

CVE-2002-1221

почти 23 года назад

BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1220

почти 23 года назад

BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1219

почти 23 года назад

Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1217

почти 23 года назад

Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2002-1216

почти 23 года назад

GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1215

почти 23 года назад

Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 694 (incorrectly claimed as TCP in some sources).

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-1214

почти 23 года назад

Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2002-1213

почти 23 года назад

Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1212

почти 23 года назад

Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1211

почти 23 года назад

Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1210

почти 23 года назад

Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1209

почти 23 года назад

Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1229

Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1228

Unknown vulnerability in NFS on Solaris 2.5.1 through Solaris 9 allows an NFS client to cause a denial of service by killing the lockd daemon.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1227

PAM 0.76 treats a disabled password as if it were an empty (null) password, which allows local and remote attackers to gain privileges as disabled users.

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1226

Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).

CVSS2: 10
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1225

Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.

CVSS2: 10
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1224

Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.

CVSS2: 5
12%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1223

Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a denial of service or execute arbitrary code via a modified .ps (PostScript) input file.

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1222

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

CVSS2: 7.1
16%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1221

BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.

CVSS2: 5
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1220

BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.

CVSS2: 5
19%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1219

Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).

CVSS2: 7.5
7%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1217

Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.

CVSS2: 7.5
73%
Высокий
почти 23 года назад
nvd логотип
CVE-2002-1216

GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1215

Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 694 (incorrectly claimed as TCP in some sources).

CVSS2: 10
15%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1214

Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.

CVSS2: 7.5
79%
Высокий
почти 23 года назад
nvd логотип
CVE-2002-1213

Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters.

CVSS2: 5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1212

Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1211

Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.

CVSS2: 7.5
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1210

Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes the script in the local browser context.

CVSS2: 5
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1209

Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.

CVSS2: 5
5%
Низкий
почти 23 года назад

Уязвимостей на страницу