Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 352

Количество 358 352

nvd логотип

CVE-2002-0730

около 24 лет назад

Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0729

около 24 лет назад

Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0728

около 24 лет назад

Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0727

почти 24 года назад

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0726

почти 24 года назад

Buffer overflow in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to execute arbitrary code via a long server name field.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0725

почти 24 года назад

NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2002-0724

почти 24 года назад

Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0723

почти 24 года назад

Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0722

почти 24 года назад

Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0721

почти 24 года назад

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-0720

почти 24 года назад

A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0719

около 24 лет назад

SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0718

около 24 лет назад

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0717

около 24 лет назад

PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0716

около 24 лет назад

Format string vulnerability in crontab for SCO OpenServer 5.0.5 and 5.0.6 allows local users to gain privileges via format string specifiers in the file name argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0715

около 24 лет назад

Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0714

около 24 лет назад

FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0713

около 24 лет назад

Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0712

больше 22 лет назад

Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0711

почти 24 года назад

Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0730

Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.

CVSS2: 7.5
7%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0729

Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.

CVSS2: 5
11%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0728

Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0727

The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.

CVSS2: 7.5
19%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0726

Buffer overflow in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to execute arbitrary code via a long server name field.

CVSS2: 7.5
17%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0725

NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file.

CVSS3: 5.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0724

Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".

CVSS2: 7.5
30%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0723

Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

CVSS2: 7.5
15%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0722

Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."

CVSS2: 7.5
13%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0721

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

CVSS2: 10
46%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0720

A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.

CVSS2: 7.2
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0719

SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.

CVSS2: 7.5
10%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0718

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."

CVSS2: 7.5
6%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0717

PHP 4.2.0 and 4.2.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP POST request with certain arguments in a multipart/form-data form, which generates an error condition that is not properly handled and causes improper memory to be freed.

CVSS2: 7.5
11%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0716

Format string vulnerability in crontab for SCO OpenServer 5.0.5 and 5.0.6 allows local users to gain privileges via format string specifiers in the file name argument.

CVSS2: 7.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0715

Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0714

FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.

CVSS2: 7.5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0713

Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.

CVSS2: 7.5
6%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0712

Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.

CVSS2: 2.1
5%
Низкий
больше 22 лет назад
nvd логотип
CVE-2002-0711

Unknown vulnerability in Cluster Interconnect for HP TruCluster Server 5.0A, 5.1, and 5.1A may allow local and remote attackers to cause a denial of service.

CVSS2: 5
3%
Низкий
почти 24 года назад

Уязвимостей на страницу