Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-0417

почти 24 года назад

Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0416

почти 24 года назад

Buffer overflow in SH39 MailServer 1.21 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long command to the SMTP port.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0415

почти 24 года назад

Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275.

CVSS2: 1.7
EPSS: Низкий
nvd логотип

CVE-2002-0414

почти 24 года назад

KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0413

почти 24 года назад

Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0412

почти 24 года назад

Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0411

почти 24 года назад

Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0410

около 24 лет назад

send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0409

около 24 лет назад

orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0408

около 24 лет назад

htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0407

около 24 лет назад

htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes htcgibin.exe to leak the pathname in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0406

около 24 лет назад

Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections to the server without providing login credentials, which prevents other users from being able to log in.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0405

около 24 лет назад

Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0404

около 24 лет назад

Vulnerability in GIOP dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (memory consumption).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0403

около 24 лет назад

DNS dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed packet that causes Ethereal to enter an infinite loop.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0402

около 24 лет назад

Buffer overflow in X11 dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code while Ethereal is parsing keysyms.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0401

около 24 лет назад

SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0400

около 24 лет назад

ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL, aka DoS_findtype.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0399

почти 24 года назад

Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0398

около 24 лет назад

Red-M 1050 (Bluetooth Access Point) PPP server allows bonded users to cause a denial of service and possibly execute arbitrary code via a long user name.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0417

Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.

CVSS2: 5
2%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0416

Buffer overflow in SH39 MailServer 1.21 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long command to the SMTP port.

CVSS2: 10
6%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0415

Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275.

CVSS2: 1.7
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0414

KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.

CVSS2: 7.5
1%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0413

Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.

CVSS2: 7.5
7%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0412

Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.

CVSS2: 7.5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0411

Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.

CVSS2: 7.5
3%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0410

send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.

CVSS2: 5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0409

orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.

CVSS2: 5
19%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0408

htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0407

htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes htcgibin.exe to leak the pathname in an error message.

CVSS2: 5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0406

Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections to the server without providing login credentials, which prevents other users from being able to log in.

CVSS2: 5
7%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0405

Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters.

CVSS2: 10
5%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0404

Vulnerability in GIOP dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (memory consumption).

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0403

DNS dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed packet that causes Ethereal to enter an infinite loop.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0402

Buffer overflow in X11 dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code while Ethereal is parsing keysyms.

CVSS2: 7.5
5%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0401

SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.

CVSS3: 7.5
6%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0400

ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL, aka DoS_findtype.

CVSS2: 5
14%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0399

Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CVE-2001-1267.

CVSS2: 5
4%
Низкий
почти 24 года назад
nvd логотип
CVE-2002-0398

Red-M 1050 (Bluetooth Access Point) PPP server allows bonded users to cause a denial of service and possibly execute arbitrary code via a long user name.

CVSS2: 10
3%
Низкий
около 24 лет назад

Уязвимостей на страницу