Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 152

Количество 307 152

nvd логотип

CVE-2002-1204

почти 23 года назад

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1203

почти 23 года назад

IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1202

почти 23 года назад

Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1201

почти 23 года назад

IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1200

почти 23 года назад

Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1199

почти 23 года назад

The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1198

почти 23 года назад

Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1197

почти 23 года назад

bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1196

почти 23 года назад

editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1195

почти 23 года назад

Cross-site scripting vulnerability (XSS) in the PHP interface for ht://Check 1.1 allows remote web servers to insert arbitrary HTML, including script, via a web page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1194

почти 23 года назад

Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1193

почти 23 года назад

tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-1192

почти 23 года назад

Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1191

почти 23 года назад

The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1190

почти 23 года назад

Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1189

почти 23 года назад

The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1188

больше 22 лет назад

Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2002-1187

больше 22 лет назад

Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2002-1186

больше 22 лет назад

Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1185

больше 22 лет назад

Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1204

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1203

IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1202

Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1201

IBM AIX 4.3.3 and AIX 5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a flood of malformed TCP packets without any flags set, which prevents AIX from releasing the associated memory buffers.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1200

Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are encountered during macro expansion, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS2: 7.5
7%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1199

The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.

CVSS2: 5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1198

Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1197

bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.

CVSS2: 7.5
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1196

editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.

CVSS2: 7.5
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1195

Cross-site scripting vulnerability (XSS) in the PHP interface for ht://Check 1.1 allows remote web servers to insert arbitrary HTML, including script, via a web page.

CVSS2: 4.3
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1194

Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.

CVSS2: 7.5
12%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1193

tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.

CVSS2: 2.1
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1192

Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.

CVSS2: 4.6
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1191

The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1190

Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1189

The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.

CVSS2: 4.6
0%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1188

Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."

CVSS2: 6.4
16%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1187

Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.

CVSS2: 6.8
27%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1186

Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."

CVSS2: 5
33%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1185

Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."

CVSS2: 5
29%
Средний
больше 22 лет назад

Уязвимостей на страницу