Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 308 751

Количество 308 751

nvd логотип

CVE-2002-2247

больше 22 лет назад

The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2246

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2245

больше 22 лет назад

ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2244

больше 22 лет назад

Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-2243

больше 22 лет назад

Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2242

больше 22 лет назад

The Apple Package Manager in KisMAC 0.02a and earlier modifies file permissions of sensitive files after installation, which could allow attackers to conduct unauthorized activities on those files.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-2241

больше 22 лет назад

Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2240

больше 22 лет назад

Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2239

больше 22 лет назад

The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2002-2238

больше 22 лет назад

Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2237

больше 22 лет назад

tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2236

больше 22 лет назад

Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-2235

больше 22 лет назад

member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2234

больше 22 лет назад

NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2233

больше 22 лет назад

Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

CVSS2: 8.3
EPSS: Низкий
nvd логотип

CVE-2002-2232

больше 22 лет назад

Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.

CVSS2: 8.5
EPSS: Средний
nvd логотип

CVE-2002-2231

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL in a photo URL or (2) an X-Forwarded-For: header.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2230

больше 22 лет назад

Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via a private message with a javascript: URL in the IMG tag, in which the URL ends in a ".gif" or ".jpg" string, a variant of CVE-2002-0328.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2229

больше 22 лет назад

Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2228

больше 22 лет назад

MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner.

CVSS2: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-2247

The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.

CVSS2: 5
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2246

Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.

CVSS2: 4.3
2%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2245

ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2244

Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2243

Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2242

The Apple Package Manager in KisMAC 0.02a and earlier modifies file permissions of sensitive files after installation, which could allow attackers to conduct unauthorized activities on those files.

CVSS2: 6.4
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2241

Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2240

Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2239

The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet.

CVSS2: 7.8
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2238

Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2237

tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2236

Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code.

CVSS2: 10
3%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2235

member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2234

NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests.

CVSS2: 4.3
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2233

Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

CVSS2: 8.3
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2232

Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.

CVSS2: 8.5
22%
Средний
больше 22 лет назад
nvd логотип
CVE-2002-2231

Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL in a photo URL or (2) an X-Forwarded-For: header.

CVSS2: 4.3
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2230

Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via a private message with a javascript: URL in the IMG tag, in which the URL ends in a ".gif" or ".jpg" string, a variant of CVE-2002-0328.

CVSS2: 4.3
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2229

Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request.

CVSS2: 5
0%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-2228

MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner.

CVSS2: 6.4
0%
Низкий
больше 22 лет назад

Уязвимостей на страницу