Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-0882

почти 24 года назад

The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2002-0881

почти 24 года назад

Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0880

почти 24 года назад

Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0879

почти 24 года назад

showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0878

почти 24 года назад

SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0877

почти 24 года назад

Directory traversal vulnerability in the FTP server for Shambala 4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) LIST (ls) or (2) GET commands.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0876

почти 24 года назад

Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0875

почти 24 года назад

Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0874

почти 24 года назад

Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0873

почти 24 года назад

Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0872

почти 24 года назад

l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0871

почти 24 года назад

xinetd 2.3.4 leaks file descriptors for the signal pipe to services that are launched by xinetd, which could allow those services to cause a denial of service via the pipe.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0870

почти 24 года назад

The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0869

больше 23 лет назад

Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0867

почти 24 года назад

Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw."

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0866

почти 24 года назад

Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka "DLL Execution via JDBC Classes."

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0865

почти 24 года назад

A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet, aka "Inappropriate Methods Exposed in XML Support Classes."

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2002-0864

почти 24 года назад

The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop."

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0863

почти 24 года назад

Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0862

почти 24 года назад

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

CVSS2: 6.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0882

The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script.

CVSS2: 6.4
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0881

Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.

CVSS2: 2.1
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0880

Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2."

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0879

showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the FILE parameter.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0878

SQL injection vulnerability in the login form for LogiSense software including (1) Hawk-i Billing, (2) Hawk-i ASP and (3) DNS Manager allows remote attackers to bypass authentication via SQL code in the password field.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0877

Directory traversal vulnerability in the FTP server for Shambala 4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the (1) LIST (ls) or (2) GET commands.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0876

Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.

CVSS2: 5
7%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0875

Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.

CVSS2: 2.1
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0874

Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.

CVSS2: 5
6%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0873

Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow.

CVSS2: 5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0872

l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0871

xinetd 2.3.4 leaks file descriptors for the signal pipe to services that are launched by xinetd, which could allow those services to cause a denial of service via the pipe.

CVSS2: 2.1
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0870

The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0869

Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."

CVSS2: 7.5
22%
Средний
больше 23 лет назад
nvd логотип
CVE-2002-0867

Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw."

CVSS2: 5
27%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0866

Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka "DLL Execution via JDBC Classes."

CVSS2: 7.5
41%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0865

A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet, aka "Inappropriate Methods Exposed in XML Support Classes."

CVSS2: 7.5
20%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0864

The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop."

CVSS2: 5
16%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0863

Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."

CVSS2: 5
22%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0862

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

CVSS2: 6.8
16%
Средний
почти 24 года назад

Уязвимостей на страницу