Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-1174

почти 24 года назад

Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1170

почти 24 года назад

The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1169

больше 23 лет назад

IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1168

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1167

больше 23 лет назад

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2002-1166

почти 24 года назад

Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1165

почти 24 года назад

Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1161

больше 23 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1380. Reason: This candidate is a reservation duplicate of CVE-2002-1380. Notes: none

EPSS: Низкий
nvd логотип

CVE-2002-1160

больше 23 лет назад

The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-1159

больше 23 лет назад

Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-1158

больше 23 лет назад

Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-1157

больше 23 лет назад

Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1156

почти 24 года назад

Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-1155

около 23 лет назад

Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-1154

почти 24 года назад

anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web server error log.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1153

почти 24 года назад

IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1152

почти 24 года назад

Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1151

почти 24 года назад

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1150

почти 24 года назад

The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and canceling out of the resulting user confirmation prompts, such as when the remote user is editing a document.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1149

почти 24 года назад

The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1174

Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, which are not properly parsed by the parse_received function.

CVSS2: 7.5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1170

The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1169

IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.

CVSS2: 5
7%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1168

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

CVSS2: 6.8
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1167

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

CVSS2: 6.8
3%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1166

Buffer overflow in John Franks WN Server 1.18.2 through 2.0.0 allows remote attackers to execute arbitrary code via a long GET request.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1165

Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

CVSS2: 4.6
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1161

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-1380. Reason: This candidate is a reservation duplicate of CVE-2002-1380. Notes: none

больше 23 лет назад
nvd логотип
CVE-2002-1160

The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1159

Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.

CVSS2: 6.4
2%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1158

Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.

CVSS2: 7.2
0%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1157

Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.

CVSS2: 7.5
10%
Низкий
больше 23 лет назад
nvd логотип
CVE-2002-1156

Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.

CVSS2: 5
13%
Средний
почти 24 года назад
nvd логотип
CVE-2002-1155

Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.

CVSS2: 7.2
1%
Низкий
около 23 лет назад
nvd логотип
CVE-2002-1154

anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web server error log.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1153

IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1152

Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1151

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.

CVSS2: 7.5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1150

The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and canceling out of the resulting user confirmation prompts, such as when the remote user is editing a document.

CVSS2: 4.6
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1149

The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings.

CVSS2: 5
2%
Низкий
почти 24 года назад

Уязвимостей на страницу