Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 343 774

Количество 343 774

nvd логотип

CVE-2002-1852

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1851

больше 23 лет назад

Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1850

больше 23 лет назад

mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1849

больше 23 лет назад

ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1848

больше 23 лет назад

TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-1847

больше 23 лет назад

Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1846

больше 23 лет назад

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1845

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1844

больше 23 лет назад

Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2002-1843

больше 23 лет назад

Perlbot 1.9.2 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $text variable in SpelCheck.pm or (2) the $filename variable in HTMLPlog.pm.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1842

больше 23 лет назад

Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1841

больше 23 лет назад

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1840

больше 23 лет назад

irssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to access the system.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1839

больше 23 лет назад

Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1838

больше 23 лет назад

Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1837

больше 23 лет назад

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1836

больше 23 лет назад

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1835

больше 23 лет назад

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1834

больше 23 лет назад

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-1833

больше 23 лет назад

The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1852

Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

CVSS2: 4.3
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1851

Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.

CVSS2: 7.5
14%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1850

mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.

CVSS3: 7.5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1849

ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1848

TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.

CVSS2: 2.1
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1847

Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.

CVSS2: 7.5
12%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1846

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1845

Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.

CVSS2: 4.3
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1844

Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.

CVSS3: 7.8
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1843

Perlbot 1.9.2 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the $text variable in SpelCheck.pm or (2) the $filename variable in HTMLPlog.pm.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1842

Perlbot 1.0 beta allows remote attackers to execute arbitrary commands via shell metacharacters in (1) a word that is being spell checked or (2) an e-mail address.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1841

The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1840

irssi IRC client 0.8.4, when downloaded after 14-March-2002, could contain a backdoor in the configuration file, which allows remote attackers to access the system.

CVSS2: 10
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1839

Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1838

Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1837

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

CVSS2: 5
7%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1836

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 exports certain NFS shares to the world with world writable permissions, which may allow remote attackers to modify sensitive files.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1835

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1834

The default configuration of Xerox DocuTech 6110 and DocuTech 6115 allows remote attackers to connect to the web server and (1) submit print jobs directly into the "print now" queue or (2) read the scanner job history.

CVSS2: 6.4
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1833

The default configurations for DocuTech 6110 and DocuTech 6115 have a default administrative password of (1) "service!" on Solaris 8.0 or (2) "administ" on Windows NT, which allows remote attackers to gain privileges.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад

Уязвимостей на страницу