Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2002-0518

больше 23 лет назад

The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced for the socket's TCP options, or (2) by killing and restarting a process that listens on the same socket, which does not properly clear the old inpcb pointer on restart.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0517

больше 23 лет назад

Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0516

больше 23 лет назад

SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0515

больше 23 лет назад

IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0514

больше 23 лет назад

PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0513

больше 23 лет назад

The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0512

больше 23 лет назад

startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0511

больше 23 лет назад

The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which could make it easier for remote attackers to bypass applications that restrict access based on host names.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0510

больше 23 лет назад

The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0509

больше 23 лет назад

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0508

больше 23 лет назад

wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0507

больше 23 лет назад

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0506

больше 23 лет назад

Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0505

больше 23 лет назад

Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0504

больше 23 лет назад

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0503

больше 23 лет назад

Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0502

больше 23 лет назад

Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0501

больше 23 лет назад

Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0500

больше 23 лет назад

Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0499

больше 23 лет назад

The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0518

The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced for the socket's TCP options, or (2) by killing and restarting a process that listens on the same socket, which does not properly clear the old inpcb pointer on restart.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0517

Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0516

SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.

CVSS2: 10
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0515

IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0514

PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0513

The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.

CVSS2: 10
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0512

startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0511

The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which could make it easier for remote attackers to bypass applications that restrict access based on host names.

CVSS2: 7.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0510

The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0509

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0508

wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.

CVSS2: 10
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0507

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

CVSS2: 2.1
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0506

Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0505

Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0504

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

CVSS2: 7.5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0503

Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0502

Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

CVSS2: 5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0501

Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.

CVSS2: 7.2
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0500

Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.

CVSS2: 5
20%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0499

The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

CVSS2: 2.1
0%
Низкий
больше 23 лет назад

Уязвимостей на страницу