Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 307 557

Количество 307 557

nvd логотип

CVE-2002-1473

больше 22 лет назад

Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

CVSS2: 4.6
EPSS: Средний
nvd логотип

CVE-2002-1472

больше 22 лет назад

Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-1471

больше 22 лет назад

The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1470

больше 22 лет назад

SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-1469

больше 22 лет назад

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1468

больше 22 лет назад

Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-1467

больше 22 лет назад

Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1466

больше 22 лет назад

CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1465

больше 22 лет назад

SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1464

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1463

около 22 лет назад

Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1462

около 22 лет назад

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1461

около 22 лет назад

Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1460

около 22 лет назад

L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1459

около 22 лет назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1458

около 22 лет назад

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1457

около 22 лет назад

SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1456

около 22 лет назад

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1455

около 22 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1454

около 22 лет назад

MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1473

Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

CVSS2: 4.6
17%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1472

Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.

CVSS2: 7.2
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1471

The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1470

SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1469

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

CVSS2: 7.5
8%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1468

Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.

CVSS2: 10
11%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-1467

Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1466

CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.

CVSS2: 10
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1465

SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1464

Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.

CVSS2: 6.8
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1463

Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 generate easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections.

CVSS2: 7.5
11%
Средний
около 22 лет назад
nvd логотип
CVE-2002-1462

details2.php in OrganicPHP PHP-affiliate 1.0, and possibly later versions, allows remote attackers to modify information of other users by modifying certain hidden form fields.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2002-1461

Web Shop Manager 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search box.

CVSS2: 7.5
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2002-1460

L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files.

CVSS2: 5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2002-1459

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

CVSS2: 7.5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2002-1458

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

CVSS2: 7.5
1%
Низкий
около 22 лет назад
nvd логотип
CVE-2002-1457

SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter.

CVSS2: 7.5
2%
Низкий
около 22 лет назад
nvd логотип
CVE-2002-1456

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

CVSS2: 7.5
15%
Средний
около 22 лет назад
nvd логотип
CVE-2002-1455

Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.

CVSS2: 4.3
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2002-1454

MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.

CVSS2: 5
1%
Низкий
около 22 лет назад

Уязвимостей на страницу