Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 614

Количество 367 614

nvd логотип

CVE-2002-0792

почти 24 года назад

The web management interface for Cisco Content Service Switch (CSS) 11000 switches allows remote attackers to cause a denial of service (soft reset) via (1) an HTTPS POST request, or (2) malformed XML data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0791

почти 24 года назад

Novell Netware FTP server NWFTPD before 5.02r allows remote attackers to cause a denial of service (CPU consumption) via a connection to the server followed by a carriage return, and possibly other invalid commands with improper syntax or length.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0790

почти 24 года назад

clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0789

почти 24 года назад

Buffer overflow in search.cgi in mnoGoSearch 3.1.19 and earlier allows remote attackers to execute arbitrary code via a long query (q) parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0788

почти 24 года назад

An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2002-0787

почти 24 года назад

Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator via administrator URLs with modified (1) LOCID or (2) OC parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0786

почти 24 года назад

iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0785

почти 24 года назад

AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0784

почти 24 года назад

Directory traversal vulnerability in Lysias Lidik web server 0.7b allows remote attackers to list directories via an HTTP request with a ... (modified dot dot).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0783

почти 24 года назад

Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the location of a frame or iframe to a Javascript: URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0782

почти 24 года назад

Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to hosts that do not have a specific route, which may be forwarded to the public interface.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0781

почти 24 года назад

RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a series of carriage returns, which causes proxy.nlm to ABEND.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0780

почти 24 года назад

IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0779

почти 24 года назад

FTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection to port 21 with a large amount of random data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0778

почти 24 года назад

The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0777

почти 24 года назад

Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-0776

почти 24 года назад

getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0775

почти 24 года назад

browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0774

почти 24 года назад

Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0773

почти 24 года назад

imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters such as (1) ftp, (2) owwwPath, and (3) oftpPath.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0792

The web management interface for Cisco Content Service Switch (CSS) 11000 switches allows remote attackers to cause a denial of service (soft reset) via (1) an HTTPS POST request, or (2) malformed XML data.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0791

Novell Netware FTP server NWFTPD before 5.02r allows remote attackers to cause a denial of service (CPU consumption) via a connection to the server followed by a carriage return, and possibly other invalid commands with improper syntax or length.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0790

clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.

CVSS2: 2.1
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0789

Buffer overflow in search.cgi in mnoGoSearch 3.1.19 and earlier allows remote attackers to execute arbitrary code via a long query (q) parameter.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0788

An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information.

CVSS3: 5.5
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0787

Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator via administrator URLs with modified (1) LOCID or (2) OC parameters.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0786

iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0785

AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow.

CVSS2: 5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0784

Directory traversal vulnerability in Lysias Lidik web server 0.7b allows remote attackers to list directories via an HTTP request with a ... (modified dot dot).

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0783

Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the location of a frame or iframe to a Javascript: URL.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0782

Novell BorderManager 3.5 with PAT (Port-Address Translate) enabled allows remote attackers to cause a denial of service by filling the connection table with a large number of connection requests to hosts that do not have a specific route, which may be forwarded to the public interface.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0781

RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a GET request to port 9090 followed by a series of carriage returns, which causes proxy.nlm to ABEND.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0780

IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service via a connection to port 8225 with a large amount of random data, which causes ipipxgw.nlm to ABEND.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0779

FTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection to port 21 with a large amount of random data.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0778

The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0777

Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter.

CVSS2: 10
10%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0776

getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0775

browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.

CVSS2: 5
8%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0774

Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed.

CVSS2: 10
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0773

imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters such as (1) ftp, (2) owwwPath, and (3) oftpPath.

CVSS2: 10
4%
Низкий
почти 24 года назад

Уязвимостей на страницу