Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 878

Количество 331 878

nvd логотип

CVE-2002-0817

больше 23 лет назад

Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0816

больше 23 лет назад

Buffer overflow in su in Tru64 Unix 5.x allows local users to gain root privileges via a long username and argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0815

больше 23 лет назад

The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0814

больше 23 лет назад

Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0813

больше 23 лет назад

Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.

CVSS2: 7.1
EPSS: Средний
nvd логотип

CVE-2002-0812

больше 23 лет назад

Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-0811

больше 23 лет назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0810

больше 23 лет назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0809

больше 23 лет назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0808

больше 23 лет назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0807

больше 23 лет назад

Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0806

больше 23 лет назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0805

больше 23 лет назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0804

больше 23 лет назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0803

больше 23 лет назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0802

больше 23 лет назад

The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0801

больше 23 лет назад

Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a .jsp file.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-0800

больше 23 лет назад

BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0799

больше 23 лет назад

Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0798

больше 23 лет назад

Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0817

Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0816

Buffer overflow in su in Tru64 Unix 5.x allows local users to gain root privileges via a long username and argument.

CVSS2: 7.2
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0815

The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0814

Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument.

CVSS2: 7.5
14%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0813

Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.

CVSS2: 7.1
10%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0812

Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.

CVSS2: 6.4
8%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0811

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi.

CVSS2: 7.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0810

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0809

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.

CVSS2: 7.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0808

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.

CVSS2: 7.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0807

Cross-site scripting vulnerabilities in Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, could allow remote attackers to execute script as other Bugzilla users via the full name (real name) field, which is not properly quoted by editusers.cgi.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0806

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows authenticated users with editing privileges to delete other users by directly calling the editusers.cgi script with the "del" option.

CVSS2: 2.1
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0805

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0804

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0803

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0802

The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks.

CVSS2: 7.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0801

Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a .jsp file.

CVSS2: 10
40%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0800

BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0799

Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument.

CVSS2: 7.5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0798

Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service.

CVSS2: 2.1
0%
Низкий
больше 23 лет назад

Уязвимостей на страницу