Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 343 977

Количество 343 977

nvd логотип

CVE-2002-2433

около 16 лет назад

NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote authenticated users to cause a denial of service (abend) via a crafted ABOR command.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2002-2432

около 16 лет назад

Unspecified vulnerability in NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via a crafted username.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2431

около 17 лет назад

Unspecified vulnerability in GoAhead WebServer before 2.1.4 allows remote attackers to cause "incorrect behavior" via unknown "malicious code," related to incorrect use of the socketInputBuffered function by sockGen.c.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-2430

около 17 лет назад

GoAhead WebServer before 2.1.1 allows remote attackers to cause a denial of service (CPU consumption) by performing a socket disconnect to terminate a request before it has been fully processed by the server.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2429

около 17 лет назад

webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2428

около 17 лет назад

webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2427

около 17 лет назад

The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2426

больше 23 лет назад

Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2425

больше 23 лет назад

Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-2424

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2423

больше 23 лет назад

Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-2422

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2421

больше 23 лет назад

acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2002-2420

больше 23 лет назад

site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-2419

больше 23 лет назад

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2002-2418

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP) 1.33 beta 7 allows remote attackers to inject arbitrary web script or HTML via the URL, which is inserted into an error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2417

больше 23 лет назад

acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-2416

больше 23 лет назад

Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2415

больше 23 лет назад

Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-2414

больше 23 лет назад

Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash).

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-2433

NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote authenticated users to cause a denial of service (abend) via a crafted ABOR command.

CVSS2: 4
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2002-2432

Unspecified vulnerability in NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via a crafted username.

CVSS2: 5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2002-2431

Unspecified vulnerability in GoAhead WebServer before 2.1.4 allows remote attackers to cause "incorrect behavior" via unknown "malicious code," related to incorrect use of the socketInputBuffered function by sockGen.c.

CVSS2: 7.5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2002-2430

GoAhead WebServer before 2.1.1 allows remote attackers to cause a denial of service (CPU consumption) by performing a socket disconnect to terminate a request before it has been fully processed by the server.

CVSS2: 5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2002-2429

webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header.

CVSS2: 5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2002-2428

webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data.

CVSS2: 5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2002-2427

The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603.

CVSS2: 5
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2002-2426

Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an ICA connection. NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2425

Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a direct request.

CVSS2: 10
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2424

Cross-site scripting (XSS) vulnerability in PHP(Reactor) 1.2.7 pl1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the style attribute of an HTML tag.

CVSS2: 4.3
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2423

Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to prevent the IP address from being logged via a long IDENT response.

CVSS2: 6.4
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2422

Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message.

CVSS2: 4.3
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2421

acWEB 1.14 allows remote attackers to cause a denial of service (crash) via an HTTP request for a MS-DOS device name such as COM2.

CVSS2: 7.8
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2420

site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.

CVSS2: 7.5
9%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2419

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte character.

CVSS2: 7.8
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2418

Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP) 1.33 beta 7 allows remote attackers to inject arbitrary web script or HTML via the URL, which is inserted into an error page.

CVSS2: 4.3
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2417

acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.

CVSS2: 10
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2416

Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request.

CVSS2: 5
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2415

Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service.

CVSS2: 6.8
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2414

Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS connection, which allows remote attackers to cause a denial of service (crash).

CVSS2: 4.3
0%
Низкий
больше 23 лет назад

Уязвимостей на страницу