Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2002-0171

больше 23 лет назад

IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0170

почти 24 года назад

Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0169

больше 23 лет назад

The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0168

почти 24 года назад

Vulnerability in Imlib before 1.9.13 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by manipulating arguments that are passed to malloc, which results in a heap corruption.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0167

почти 24 года назад

Imlib before 1.9.13 sometimes uses the NetPBM package to load trusted images, which could allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain weaknesses of NetPBM.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0166

почти 24 года назад

Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0165

почти 24 года назад

LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CVE-2002-0162.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0164

почти 24 года назад

Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0163

почти 24 года назад

Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via compressed DNS responses.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0162

почти 24 года назад

LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-2002-0160

почти 24 года назад

The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0159

почти 24 года назад

Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0158

почти 24 года назад

Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0157

больше 23 лет назад

Nautilus 1.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the .nautilus-metafile.xml metadata file.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0155

больше 23 лет назад

Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0154

больше 23 лет назад

Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0153

почти 24 года назад

Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0152

почти 24 года назад

Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0151

почти 24 года назад

Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0150

почти 24 года назад

Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0171

IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0170

Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0169

The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0168

Vulnerability in Imlib before 1.9.13 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by manipulating arguments that are passed to malloc, which results in a heap corruption.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0167

Imlib before 1.9.13 sometimes uses the NetPBM package to load trusted images, which could allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain weaknesses of NetPBM.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0166

Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0165

LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CVE-2002-0162.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0164

Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0163

Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via compressed DNS responses.

CVSS2: 7.5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0162

LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.

CVSS2: 6.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0160

The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) in the URL to port 2002.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0159

Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0158

Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0157

Nautilus 1.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the .nautilus-metafile.xml metadata file.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0155

Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.

CVSS2: 7.5
19%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0154

Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.

CVSS2: 7.5
24%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0153

Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability.

CVSS2: 7.5
25%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0152

Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.

CVSS2: 7.5
23%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0151

Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.

CVSS2: 7.2
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0150

Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.

CVSS2: 7.5
68%
Средний
почти 24 года назад

Уязвимостей на страницу