Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-1105

почти 24 года назад

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-1104

почти 24 года назад

Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1103

почти 24 года назад

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1102

почти 24 года назад

The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1101

почти 24 года назад

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1100

почти 24 года назад

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1099

почти 24 года назад

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1098

почти 24 года назад

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1097

почти 24 года назад

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1096

почти 24 года назад

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1095

почти 24 года назад

Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1094

почти 24 года назад

Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1093

почти 24 года назад

HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1092

почти 24 года назад

Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1091

почти 24 года назад

Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1090

почти 24 года назад

Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1089

почти 24 года назад

rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1088

почти 24 года назад

Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-1087

почти 24 года назад

The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-1086

почти 24 года назад

Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1105

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1104

Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1103

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1102

The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous connection.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1101

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1100

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1099

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1098

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1097

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1096

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1095

Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1094

Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1093

HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1092

Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1091

Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.

CVSS2: 7.5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1090

Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1089

rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.

CVSS2: 5
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1088

Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1087

The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-1086

Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.

CVSS2: 7.5
2%
Низкий
почти 24 года назад

Уязвимостей на страницу