Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 343 004

Количество 343 004

nvd логотип

CVE-2002-0723

больше 23 лет назад

Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0722

больше 23 лет назад

Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0721

больше 23 лет назад

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-0720

больше 23 лет назад

A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0719

больше 23 лет назад

SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0718

больше 23 лет назад

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0717

больше 23 лет назад

PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0716

больше 23 лет назад

Format string vulnerability in crontab for SCO OpenServer 5.0.5 and 5.0.6 allows local users to gain privileges via format string specifiers in the file name argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0715

больше 23 лет назад

Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0714

больше 23 лет назад

FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0713

больше 23 лет назад

Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0712

около 22 лет назад

Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0711

больше 23 лет назад

Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0710

больше 23 лет назад

Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-0709

больше 23 лет назад

SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0708

больше 23 лет назад

Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0707

больше 23 лет назад

The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0706

больше 23 лет назад

UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0705

больше 23 лет назад

The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0704

больше 23 лет назад

The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error messages.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0723

Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

CVSS2: 7.5
22%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0722

Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."

CVSS2: 7.5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0721

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

CVSS2: 10
48%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0720

A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.

CVSS2: 7.2
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0719

SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.

CVSS2: 7.5
6%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0718

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."

CVSS2: 7.5
9%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0717

PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.

CVSS2: 7.5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0716

Format string vulnerability in crontab for SCO OpenServer 5.0.5 and 5.0.6 allows local users to gain privileges via format string specifiers in the file name argument.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0715

Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.

CVSS2: 5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0714

FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.

CVSS2: 7.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0713

Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0712

Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.

CVSS2: 2.1
0%
Низкий
около 22 лет назад
nvd логотип
CVE-2002-0711

Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0710

Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter.

CVSS2: 6.4
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0709

SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0708

Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.

CVSS2: 5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0707

The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0706

UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.

CVSS2: 7.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0705

The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-0704

The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error messages.

CVSS3: 7.5
1%
Низкий
больше 23 лет назад

Уязвимостей на страницу