Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 343 490

Количество 343 490

nvd логотип

CVE-2002-1366

больше 23 лет назад

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-2002-1365

больше 23 лет назад

Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local addresses.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1364

больше 23 лет назад

Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-1363

больше 23 лет назад

Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1362

больше 23 лет назад

mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1361

больше 23 лет назад

overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-1360

больше 23 лет назад

Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1359

больше 23 лет назад

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
EPSS: Высокий
nvd логотип

CVE-2002-1358

больше 23 лет назад

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1357

больше 23 лет назад

Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-1356

больше 23 лет назад

Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1355

больше 23 лет назад

Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1354

больше 23 лет назад

Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1353

больше 23 лет назад

LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1352

больше 22 лет назад

Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product prices by changing the price parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1351

больше 23 лет назад

Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1350

больше 23 лет назад

The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1349

больше 23 лет назад

Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1348

около 23 лет назад

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1347

больше 23 лет назад

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1366

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.

CVSS2: 6.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1365

Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local addresses.

CVSS2: 7.5
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1364

Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.

CVSS2: 7.2
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1363

Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.

CVSS2: 7.5
7%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1362

mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1361

overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.

CVSS2: 10
21%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1360

Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1359

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
87%
Высокий
больше 23 лет назад
nvd логотип
CVE-2002-1358

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1357

Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

CVSS2: 10
21%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1356

Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages.

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1355

Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1354

Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1353

LocalWEB2000 HTTP server 2.1.0 stores passwords in plain text under the web document root in users.lst, which allows remote attackers to obtain the passwords via a direct request to users.lst.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1352

Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product prices by changing the price parameter.

CVSS2: 5
1%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-1351

Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request.

CVSS2: 5
29%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1350

The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).

CVSS2: 7.5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1349

Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1348

w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.

CVSS2: 5
1%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1347

Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string.

CVSS3: 9.8
10%
Низкий
больше 23 лет назад

Уязвимостей на страницу