Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 308 633

Количество 308 633

nvd логотип

CVE-2002-2289

больше 22 лет назад

soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2288

больше 22 лет назад

Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2287

больше 22 лет назад

PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-2286

больше 22 лет назад

The parse-get function in utils.c for apt-www-proxy 0.1 allows remote attackers to cause a denial of service (crash) via an empty HTTP request, which causes a null dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2285

больше 22 лет назад

eTrust InoculateIT 6.0 with the "Incremental Scan" option enabled may certify that a file is free of viruses before the file has been completely downloaded, which allows remote attackers to bypass virus detection.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2284

больше 22 лет назад

Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-2283

больше 22 лет назад

Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users.

CVSS2: 1.9
EPSS: Низкий
nvd логотип

CVE-2002-2282

больше 22 лет назад

McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs.

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2002-2281

больше 22 лет назад

Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-2280

больше 22 лет назад

syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-2279

больше 22 лет назад

Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-2278

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2277

больше 22 лет назад

SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_file, (4) $BD_Tab_liens, (5) $BD_Tab_faq, or (6) $chemin variables.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-2276

больше 22 лет назад

Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2275

больше 22 лет назад

Fortres 101 4.1 allows local users to bypass Fortres by pressing the Windows and "F" key together for 30 seconds, which opens multiple windows and eventually causes explorer.exe to crash, which then opens an unrestricted explorer.exe.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-2274

больше 22 лет назад

akfingerd 0.5 allows local users to read arbitrary files as the akfingerd user (nobody) via a symlink attack on the .plan file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-2273

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows remote attackers to inject arbitrary web script or HTML via the URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2272

больше 22 лет назад

Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.

CVSS2: 7.8
EPSS: Средний
nvd логотип

CVE-2002-2271

больше 22 лет назад

Buffer overflow in BigFun 1.51b IRC client, when the Direct Client Connection (DCC) option is used, allows remote attackers to cause a denial of service (crash) via a long string.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2270

больше 22 лет назад

Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.

CVSS2: 3.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-2289

soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2288

Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.

CVSS2: 5
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2287

PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

CVSS2: 7.5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2286

The parse-get function in utils.c for apt-www-proxy 0.1 allows remote attackers to cause a denial of service (crash) via an empty HTTP request, which causes a null dereference.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2285

eTrust InoculateIT 6.0 with the "Incremental Scan" option enabled may certify that a file is free of viruses before the file has been completely downloaded, which allows remote attackers to bypass virus detection.

CVSS2: 4.3
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2284

Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.

CVSS2: 6.4
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2283

Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users.

CVSS2: 1.9
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2282

McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs.

CVSS2: 6.9
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2281

Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler.

CVSS2: 10
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2280

syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2279

Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions.

CVSS2: 10
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2278

Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables.

CVSS2: 4.3
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2277

SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_file, (4) $BD_Tab_liens, (5) $BD_Tab_faq, or (6) $chemin variables.

CVSS2: 7.5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2276

Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2275

Fortres 101 4.1 allows local users to bypass Fortres by pressing the Windows and "F" key together for 30 seconds, which opens multiple windows and eventually causes explorer.exe to crash, which then opens an unrestricted explorer.exe.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2274

akfingerd 0.5 allows local users to read arbitrary files as the akfingerd user (nobody) via a symlink attack on the .plan file.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2273

Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows remote attackers to inject arbitrary web script or HTML via the URL.

CVSS2: 4.3
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2272

Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.

CVSS2: 7.8
21%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-2271

Buffer overflow in BigFun 1.51b IRC client, when the Direct Client Connection (DCC) option is used, allows remote attackers to cause a denial of service (crash) via a long string.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2270

Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.

CVSS2: 3.6
0%
Низкий
больше 22 лет назад

Уязвимостей на страницу