Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 115

Количество 372 115

nvd логотип

CVE-2002-1712

больше 23 лет назад

Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1711

больше 23 лет назад

BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-1710

больше 23 лет назад

The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2002-1709

больше 23 лет назад

SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-1708

больше 23 лет назад

Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1707

больше 23 лет назад

install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir parameter to reference a URL on a remote web server that contains the code.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1706

больше 23 лет назад

Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data Over Cable Service Interface Specification (DOCSIS) settings via a DOCSIS file without a Message Integrity Check (MIC) signature, which is approved by the router.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1705

больше 23 лет назад

Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1704

больше 23 лет назад

Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on a remote web server that contains the code.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1703

больше 23 лет назад

Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users via the Term parameter.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1702

больше 23 лет назад

Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2002-1700

больше 23 лет назад

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2002-1699

больше 23 лет назад

SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-1698

больше 23 лет назад

Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1697

больше 23 лет назад

Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same ciphertext from the same plaintext blocks, which could allow remote attackers to gain sensitive information.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1696

больше 23 лет назад

Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2002-1695

больше 23 лет назад

Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1694

больше 23 лет назад

Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1692

больше 23 лет назад

Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2002-1691

больше 23 лет назад

Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1712

Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.

CVSS2: 5
26%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1711

BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments.

CVSS2: 2.1
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1710

The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file.

CVSS2: 3.6
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1709

SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.

CVSS2: 6.4
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1708

Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.

CVSS2: 6.8
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1707

install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir parameter to reference a URL on a remote web server that contains the code.

CVSS2: 5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1706

Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data Over Cable Service Interface Specification (DOCSIS) settings via a DOCSIS file without a Message Integrity Check (MIC) signature, which is approved by the router.

CVSS3: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1705

Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.

CVSS2: 5
18%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1704

Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on a remote web server that contains the code.

CVSS2: 5
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1703

Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users via the Term parameter.

CVSS2: 6.8
4%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1702

Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as other users via the URL parameter.

CVSS2: 4.3
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1700

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

CVSS2: 4.3
23%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1699

SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.

CVSS2: 10
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1698

Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.

CVSS2: 5
16%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1697

Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same ciphertext from the same plaintext blocks, which could allow remote attackers to gain sensitive information.

CVSS3: 7.5
1%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1696

Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.

CVSS3: 5.5
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1695

Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.

CVSS2: 5
13%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1694

Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.

CVSS2: 5
12%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-1692

Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up.

CVSS2: 3.6
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1691

Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access.

CVSS2: 10
4%
Низкий
больше 23 лет назад

Уязвимостей на страницу