Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 152

Количество 307 152

nvd логотип

CVE-2002-1184

почти 23 года назад

The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1183

больше 22 лет назад

Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1182

почти 23 года назад

IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1181

почти 23 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2002-1180

почти 23 года назад

A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1179

почти 23 года назад

Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1178

почти 23 года назад

Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1177

больше 22 лет назад

Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1176

больше 22 лет назад

Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1175

почти 23 года назад

The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1174

почти 23 года назад

Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1170

почти 23 года назад

The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1169

почти 23 года назад

IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1168

почти 23 года назад

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1167

почти 23 года назад

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1166

почти 23 года назад

Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1165

почти 23 года назад

Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1161

больше 22 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1380. Reason: This candidate is a reservation duplicate of CVE-2002-1380. Notes: none

EPSS: Низкий
nvd логотип

CVE-2002-1160

больше 22 лет назад

The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-1159

больше 22 лет назад

Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.

CVSS2: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1184

The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.

CVSS2: 4.6
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1183

Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).

CVSS2: 7.5
12%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1182

IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.

CVSS2: 5
25%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1181

Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.

CVSS2: 6.8
21%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1180

A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."

CVSS2: 7.5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1179

Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.

CVSS2: 7.5
46%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1178

Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.

CVSS2: 5
10%
Средний
почти 23 года назад
nvd логотип
CVE-2002-1177

Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1176

Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.

CVSS2: 7.5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1175

The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to read data beyond the expected boundary.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1174

Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function.

CVSS2: 7.5
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1170

The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.

CVSS2: 5
1%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1169

IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.

CVSS2: 5
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1168

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

CVSS2: 6.8
2%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1167

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

CVSS2: 6.8
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1166

Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request.

CVSS2: 7.5
4%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1165

Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

CVSS2: 4.6
3%
Низкий
почти 23 года назад
nvd логотип
CVE-2002-1161

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1380. Reason: This candidate is a reservation duplicate of CVE-2002-1380. Notes: none

больше 22 лет назад
nvd логотип
CVE-2002-1160

The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.

CVSS2: 7.2
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1159

Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.

CVSS2: 6.4
1%
Низкий
больше 22 лет назад

Уязвимостей на страницу