Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 149

Количество 371 149

nvd логотип

CVE-2002-1866

больше 23 лет назад

Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1865

больше 23 лет назад

Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1864

больше 23 лет назад

Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1863

больше 23 лет назад

Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1862

больше 23 лет назад

SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1861

больше 23 лет назад

Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1860

больше 23 лет назад

Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1859

больше 23 лет назад

Orion Application Server 1.5.3, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1858

больше 23 лет назад

Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1857

больше 23 лет назад

jo! jo Webserver 1.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1856

больше 23 лет назад

HP Application Server 8.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1855

больше 23 лет назад

Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1854

больше 23 лет назад

Rlaj whois CGI script (whois.cgi) 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain name field.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1853

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the subject of a newsgroup post, which is not properly handled by (1) myarticles.php, (2) search.php, (3) stats.php, or (4) standard.lib.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1852

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1851

больше 23 лет назад

Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1850

больше 23 лет назад

mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2002-1849

больше 23 лет назад

ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1848

больше 23 лет назад

TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-1847

больше 23 лет назад

Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1866

Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1865

Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via a long header, as demonstrated using the Host header.

CVSS2: 5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1864

Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.

CVSS2: 5
18%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1863

Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled.

CVSS2: 4.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1862

SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.

CVSS2: 5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1861

Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1860

Pramati Server 3.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1859

Orion Application Server 1.5.3, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1858

Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1857

jo! jo Webserver 1.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1856

HP Application Server 8.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1855

Macromedia JRun 3.0 through 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1854

Rlaj whois CGI script (whois.cgi) 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain name field.

CVSS2: 10
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1853

Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the subject of a newsgroup post, which is not properly handled by (1) myarticles.php, (2) search.php, (3) stats.php, or (4) standard.lib.php.

CVSS2: 4.3
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1852

Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

CVSS2: 4.3
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1851

Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.

CVSS2: 7.5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1850

mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.

CVSS3: 7.5
15%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1849

ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users.

CVSS2: 5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1848

TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.

CVSS2: 2.1
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1847

Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.

CVSS2: 7.5
34%
Средний
больше 23 лет назад

Уязвимостей на страницу