Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2002-0438

больше 23 лет назад

ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall's IP address and an incorrect MAC address, which causes the firewall to disable the LAN interface.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0437

больше 23 лет назад

Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format vulnerability" by some sources.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0436

больше 23 лет назад

sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0435

больше 23 лет назад

Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2002-0434

больше 23 лет назад

Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0433

больше 23 лет назад

Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0432

больше 23 лет назад

Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attacks such as a long HELO command to the SMTP server.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0431

больше 23 лет назад

XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0430

больше 23 лет назад

MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.

CVSS2: 3.7
EPSS: Низкий
nvd логотип

CVE-2002-0429

больше 23 лет назад

The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to kill arbitrary processes via a a binary compatibility interface (lcall).

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2002-0428

больше 23 лет назад

Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0427

больше 23 лет назад

Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0426

больше 23 лет назад

VPN Server module in Linksys EtherFast BEFVP41 Cable/DSL VPN Router before 1.40.1 reduces the key lengths for keys that are supplied via manual key entry, which makes it easier for attackers to crack the keys.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0425

больше 23 лет назад

mIRC DCC server protocol allows remote attackers to gain sensitive information such as alternate IRC nicknames via a "100 testing" message in a DCC connection request that cannot be ignored or canceled by the user, which may leak the alternate nickname in a response message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0424

больше 23 лет назад

efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0423

больше 23 лет назад

Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0422

больше 23 лет назад

IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header.

CVSS2: 2.6
EPSS: Средний
nvd логотип

CVE-2002-0421

больше 23 лет назад

IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0420

больше 23 лет назад

Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0419

больше 23 лет назад

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0438

ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall's IP address and an incorrect MAC address, which causes the firewall to disable the LAN interface.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0437

Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format vulnerability" by some sources.

CVSS2: 10
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0436

sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.

CVSS2: 10
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0435

Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.

CVSS2: 1.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0434

Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.

CVSS2: 10
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0433

Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0432

Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attacks such as a long HELO command to the SMTP server.

CVSS2: 10
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0431

XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.

CVSS2: 5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0430

MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.

CVSS2: 3.7
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0429

The iBCS routines in arch/i386/kernel/traps.c for Linux kernels 2.4.18 and earlier on x86 systems allow local users to kill arbitrary processes via a a binary compatibility interface (lcall).

CVSS2: 3.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0428

Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file.

CVSS2: 7.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0427

Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges.

CVSS2: 10
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0426

VPN Server module in Linksys EtherFast BEFVP41 Cable/DSL VPN Router before 1.40.1 reduces the key lengths for keys that are supplied via manual key entry, which makes it easier for attackers to crack the keys.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0425

mIRC DCC server protocol allows remote attackers to gain sensitive information such as alternate IRC nicknames via a "100 testing" message in a DCC connection request that cannot be ignored or canceled by the user, which may leak the alternate nickname in a response message.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0424

efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0423

Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup.

CVSS2: 10
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0422

IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header.

CVSS2: 2.6
66%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0421

IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.

CVSS2: 5
24%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0420

Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0419

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request. NOTE: this entry originally contained a vector (1) in which the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages. CVE has REJECTED this vector; it is not a vulnerability because the information is already available through legitimate use, since authentication cannot proceed without specifying a scheme that is supported by both the client and the server.

CVSS2: 5
31%
Средний
больше 23 лет назад

Уязвимостей на страницу