Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2002-0355

больше 23 лет назад

netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0354

больше 23 лет назад

The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0353

больше 23 лет назад

The ASN.1 parser in Ethereal 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a certain malformed packet, which causes Ethereal to allocate memory incorrectly, possibly due to zero-length fields.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0352

больше 23 лет назад

Phorum 3.3.2 allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the stats.php program, which does not require authentication.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0351

больше 23 лет назад

Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0350

больше 23 лет назад

HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2002-0349

больше 23 лет назад

Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0348

больше 23 лет назад

service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0347

больше 23 лет назад

Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0346

больше 23 лет назад

Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0345

больше 23 лет назад

Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0344

больше 23 лет назад

Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0343

больше 23 лет назад

Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0342

больше 23 лет назад

Kmail 1.2 on KDE 2.1.1 allows remote attackers to cause a denial of service (crash) via an email message whose body is approximately 55 K long.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0341

больше 23 лет назад

GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0340

больше 23 лет назад

Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via Trojan horse files containing .wmf content.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0339

больше 23 лет назад

Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0338

больше 23 лет назад

The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0337

больше 23 лет назад

RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files.

CVSS2: 5.4
EPSS: Низкий
nvd логотип

CVE-2002-0336

больше 23 лет назад

Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0355

netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.

CVSS2: 2.1
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0354

The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0353

The ASN.1 parser in Ethereal 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a certain malformed packet, which causes Ethereal to allocate memory incorrectly, possibly due to zero-length fields.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0352

Phorum 3.3.2 allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the stats.php program, which does not require authentication.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0351

Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0350

HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service.

CVSS2: 7.8
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0349

Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0348

service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.

CVSS2: 7.5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0347

Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.

CVSS2: 5
8%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0346

Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.

CVSS2: 7.5
12%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0345

Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0344

Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0343

Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0342

Kmail 1.2 on KDE 2.1.1 allows remote attackers to cause a denial of service (crash) via an email message whose body is approximately 55 K long.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0341

GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0340

Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via Trojan horse files containing .wmf content.

CVSS2: 7.5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0339

Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0338

The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.

CVSS2: 5
10%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0337

RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files.

CVSS2: 5.4
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0336

Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.

CVSS2: 7.5
11%
Средний
больше 23 лет назад

Уязвимостей на страницу