Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-2378

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2377

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2376

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue might overlap CVE-2005-1605.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2375

больше 23 лет назад

Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding directory structure than is already available to any CommuniGate Pro user, although there is a possibility that it could be used to infer product version information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2374

больше 23 лет назад

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-2373

больше 23 лет назад

The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-2372

больше 23 лет назад

The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2371

больше 23 лет назад

Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2002-2370

больше 23 лет назад

SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2369

больше 23 лет назад

Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-2368

больше 23 лет назад

Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long username to (1) the GetString function in proxy.c for the SOCKS5 module or (2) the HandleS4Connection function in proxy.c for the SOCKS4 module.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-2367

больше 23 лет назад

Off-by-one buffer overflow in NEC SOCKS5 1.0 r11 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hostname.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2002-2366

больше 23 лет назад

Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a skin with a long colors file name in trillian.xml.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-2365

больше 23 лет назад

Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-2364

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2363

больше 23 лет назад

VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-2362

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-2361

больше 23 лет назад

The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2002-2360

больше 23 лет назад

The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2002-2359

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-2378

Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page.

CVSS2: 4.3
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2377

Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.

CVSS2: 4.3
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2376

Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary SSI directives, web script, and HTML via the (1) full name, (2) email, (3) homepage, and (4) location parameters. NOTE: this issue might overlap CVE-2005-1605.

CVSS2: 4.3
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2375

Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding directory structure than is already available to any CommuniGate Pro user, although there is a possibility that it could be used to infer product version information.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2374

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

CVSS2: 10
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2373

The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access.

CVSS2: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2372

The telnet server in Infoprint 21 running controller software before 1.056007 allows remote attackers to cause a denial of service (crash) via a long username, possibly due to a buffer overflow.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2371

Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header.

CVSS2: 7.8
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2370

SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.

CVSS2: 5
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2369

Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2368

Multiple buffer overflows in NEC SOCKS5 1.0 r11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long username to (1) the GetString function in proxy.c for the SOCKS5 module or (2) the HandleS4Connection function in proxy.c for the SOCKS4 module.

CVSS2: 10
7%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2367

Off-by-one buffer overflow in NEC SOCKS5 1.0 r11 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long hostname.

CVSS2: 7.8
5%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2366

Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a skin with a long colors file name in trillian.xml.

CVSS2: 6.8
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2365

Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.

CVSS2: 10
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2364

Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.

CVSS2: 4.3
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2363

VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2362

Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.

CVSS2: 4.3
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2361

The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.

CVSS2: 5.8
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2360

The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary files and execute arbitrary commands via remote_foreign_require and remote_foreign_call requests.

CVSS2: 9.3
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-2359

Cross-site scripting (XSS) vulnerability in the FTP view feature in Mozilla 1.0 allows remote attackers to inject arbitrary web script or HTML via the title tag of an ftp URL.

CVSS2: 4.3
4%
Низкий
больше 23 лет назад

Уязвимостей на страницу