Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 863

Количество 371 863

nvd логотип

CVE-2002-0234

около 24 лет назад

NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2002-0233

около 24 лет назад

Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0232

около 24 лет назад

Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0231

около 24 лет назад

Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0230

около 24 лет назад

Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0229

около 24 лет назад

Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0228

около 24 лет назад

Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0227

около 24 лет назад

KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0226

около 24 лет назад

retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0225

около 24 лет назад

tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2002-0224

около 24 лет назад

The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2002-0223

около 24 лет назад

Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0222

около 24 лет назад

Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0221

около 24 лет назад

Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0220

около 24 лет назад

phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0219

около 24 лет назад

Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0218

около 24 лет назад

Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2002-0217

около 24 лет назад

Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2002-0216

около 24 лет назад

userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2002-0215

около 24 лет назад

Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-0234

NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections.

CVSS2: 2.1
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0233

Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0232

Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0231

Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.

CVSS2: 7.5
10%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0230

Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.

CVSS2: 5
8%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0229

Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

CVSS2: 7.5
9%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0228

Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).

CVSS2: 5
16%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0227

KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.

CVSS2: 5
3%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0226

retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0225

tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.

CVSS2: 4.6
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0224

The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.

CVSS2: 5
21%
Средний
около 24 лет назад
nvd логотип
CVE-2002-0223

Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0222

Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0221

Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV.

CVSS2: 5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0220

phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0219

Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.

CVSS2: 7.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0218

Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.

CVSS2: 7.2
0%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0217

Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.

CVSS2: 7.5
2%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0216

userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.

CVSS2: 5
1%
Низкий
около 24 лет назад
nvd логотип
CVE-2002-0215

Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.

CVSS2: 5
7%
Низкий
около 24 лет назад

Уязвимостей на страницу