Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-0517

почти 24 года назад

Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0516

почти 24 года назад

SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2002-0515

почти 24 года назад

IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0514

почти 24 года назад

PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0513

почти 24 года назад

The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0512

почти 24 года назад

startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0511

почти 24 года назад

The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which could make it easier for remote attackers to bypass applications that restrict access based on host names.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0510

почти 24 года назад

The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0509

почти 24 года назад

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0508

почти 24 года назад

wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0507

почти 24 года назад

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0506

почти 24 года назад

Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0505

почти 24 года назад

Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0504

почти 24 года назад

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0503

почти 24 года назад

Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0502

почти 24 года назад

Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0501

почти 24 года назад

Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0500

почти 24 года назад

Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0499

почти 24 года назад

The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0498

почти 24 года назад

Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0517

Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0516

SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.

CVSS2: 10
11%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0515

IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0514

PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0513

The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.

CVSS2: 10
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0512

startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries.

CVSS2: 4.6
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0511

The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which could make it easier for remote attackers to bypass applications that restrict access based on host names.

CVSS2: 7.5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0510

The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0509

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.

CVSS2: 5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0508

wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.

CVSS2: 10
5%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0507

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

CVSS2: 2.1
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0506

Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.

CVSS2: 7.2
0%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0505

Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0504

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

CVSS2: 7.5
8%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0503

Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0502

Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

CVSS2: 5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0501

Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.

CVSS2: 7.2
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0500

Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.

CVSS2: 5
15%
Средний
почти 24 года назад
nvd логотип
CVE-2002-0499

The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

CVSS2: 2.1
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0498

Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users.

CVSS2: 4.6
0%
Низкий
почти 24 года назад

Уязвимостей на страницу