Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-0314

около 24 лет назад

fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0313

около 24 лет назад

Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0312

около 24 лет назад

Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0311

около 24 лет назад

Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0310

около 24 лет назад

Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0309

около 24 лет назад

SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to determine certain firewall configuration information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0308

около 24 лет назад

admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2002-0307

около 24 лет назад

Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl's eval function.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0306

около 24 лет назад

ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0305

около 24 лет назад

Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0304

около 24 лет назад

Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0303

около 24 лет назад

GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0302

около 24 лет назад

The Notify daemon for Symantec Enterprise Firewall (SEF) 6.5.x drops large alerts when SNMP is used as the transport, which could prevent some alerts from being sent in the event of an attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0301

около 24 лет назад

Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0300

около 24 лет назад

gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0299

около 24 лет назад

CNet CatchUp before 1.3.1 allows attackers to execute arbitrary code via a .RVP file that creates a file with an arbitrary extension (such as .BAT), which is executed during a scan.

CVSS2: 7.6
EPSS: Низкий
nvd логотип

CVE-2002-0298

около 24 лет назад

ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0297

около 24 лет назад

Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0296

около 24 лет назад

The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2002-0295

около 24 лет назад

Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0314

fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0313

Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.

CVSS2: 7.5
10%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0312

Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0311

Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.

CVSS2: 10
5%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0310

Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0309

SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to determine certain firewall configuration information.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0308

admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.

CVSS2: 10
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0307

Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl's eval function.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0306

ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.

CVSS2: 7.5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0305

Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0304

Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0303

GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0302

The Notify daemon for Symantec Enterprise Firewall (SEF) 6.5.x drops large alerts when SNMP is used as the transport, which could prevent some alerts from being sent in the event of an attack.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0301

Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0300

gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and does not process the requested file.

CVSS2: 5
7%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0299

CNet CatchUp before 1.3.1 allows attackers to execute arbitrary code via a .RVP file that creates a file with an arbitrary extension (such as .BAT), which is executed during a scan.

CVSS2: 7.6
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0298

ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0297

Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0296

The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.

CVSS2: 1.2
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0295

Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.

CVSS2: 4.6
0%
Низкий
около 24 лет назад

Уязвимостей на страницу