Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 149

Количество 371 149

nvd логотип

CVE-2002-0827

почти 24 года назад

Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0826

почти 24 года назад

Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary code via a long SITE CPWD command.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0825

почти 24 года назад

Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0824

почти 24 года назад

BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2002-0823

почти 24 года назад

Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0822

почти 24 года назад

Ethereal 0.9.4 and earlier allows remote attackers to cause a denial of service and possibly excecute arbitrary code via the (1) SOCKS, (2) RSVP, (3) AFS, or (4) LMP dissectors, which can be caused to core dump.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0821

почти 24 года назад

Buffer overflows in Ethereal 0.9.4 and earlier allow remote attackers to cause a denial of service or execute arbitrary code via (1) the BGP dissector, or (2) the WCP dissector.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0820

почти 24 года назад

FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0819

почти 24 года назад

Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly handled in a call to the arts_fatal function.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0818

почти 24 года назад

wwwoffled in World Wide Web Offline Explorer (WWWOFFLE) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative Content-Length value.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0817

почти 24 года назад

Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0816

почти 24 года назад

Buffer overflow in su in Tru64 Unix 5.x allows local users to gain root privileges via a long username and argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0815

почти 24 года назад

The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0814

почти 24 года назад

Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0813

почти 24 года назад

Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.

CVSS2: 7.1
EPSS: Низкий
nvd логотип

CVE-2002-0812

почти 24 года назад

Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-0811

почти 24 года назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0810

почти 24 года назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0809

почти 24 года назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0808

почти 24 года назад

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0827

Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0826

Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary code via a long SITE CPWD command.

CVSS2: 7.5
12%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0825

Buffer overflow in the DNS SRV code for nss_ldap before nss_ldap-198 allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0824

BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.

CVSS2: 6.9
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0823

Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter.

CVSS2: 7.5
26%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0822

Ethereal 0.9.4 and earlier allows remote attackers to cause a denial of service and possibly excecute arbitrary code via the (1) SOCKS, (2) RSVP, (3) AFS, or (4) LMP dissectors, which can be caused to core dump.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0821

Buffer overflows in Ethereal 0.9.4 and earlier allow remote attackers to cause a denial of service or execute arbitrary code via (1) the BGP dissector, or (2) the WCP dissector.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0820

FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0819

Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly handled in a call to the arts_fatal function.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0818

wwwoffled in World Wide Web Offline Explorer (WWWOFFLE) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative Content-Length value.

CVSS2: 7.5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0817

Format string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.

CVSS2: 7.2
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0816

Buffer overflow in su in Tru64 Unix 5.x allows local users to gain root privileges via a long username and argument.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0815

The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.

CVSS2: 7.5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0814

Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument.

CVSS2: 7.5
14%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0813

Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.

CVSS2: 7.1
9%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0812

Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.

CVSS2: 6.4
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0811

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL injection attack on the sort order parameter to buglist.cgi.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0810

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0809

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0808

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.

CVSS2: 7.5
1%
Низкий
почти 24 года назад

Уязвимостей на страницу