VYPR

CVEs

343,040 total · page 6740 of 6,861

  • CVE-2002-1966Dec 31, 2002
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

  • CVE-2002-1967Dec 31, 2002
    risk 0.00cvss epss 0.02

    Buffer overflow in XiRCON 1.0 Beta 4 allows remote attackers to cause a denial of service (disconnect) via a long (1) ctcp, (2) primsg, (3) msg, or (4) notice command.

  • CVE-2002-1968Dec 31, 2002
    risk 0.00cvss epss 0.00

    Com21 DOXport 1100 series cable modem running firmware 2.1.1.106, and possibly other versions before 2.1.1.108.003, downloads a DOCSIS configuration file from a TFTP server running on the internal network, which allows local users to modify configuration of the modem via a…

  • CVE-2002-1969Dec 31, 2002
    risk 0.00cvss epss 0.01

    Magic Notebook 1.0b and 1.1b allows remote attackers to cause a denial of service (crash) via an invalid username during login.

  • CVE-2002-1970Dec 31, 2002
    risk 0.00cvss epss 0.00

    SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.

  • CVE-2002-1971Dec 31, 2002
    risk 0.00cvss epss 0.04

    The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.

  • CVE-2002-1972Dec 31, 2002
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Parallel port powerSwitch (aka pp_powerSwitch) 0.1 does not properly enforce access controls, which allows local users to access arbitrary ports.

  • CVE-2002-1973Dec 31, 2002
    risk 0.06cvss epss 0.40

    Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of…

  • CVE-2002-1974Dec 31, 2002
    risk 0.00cvss epss 0.03

    The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.

  • CVE-2002-1975MedDec 31, 2002
    risk 0.36cvss 5.5epss 0.00

    Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.

  • CVE-2002-1976Dec 31, 2002
    risk 0.00cvss epss 0.00

    ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demonstrated using libpcap.

  • CVE-2002-1977Dec 31, 2002
    risk 0.00cvss epss 0.00

    Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.

  • CVE-2002-1978Dec 31, 2002
    risk 0.00cvss epss 0.02

    IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a…

  • CVE-2002-1979Dec 31, 2002
    risk 0.00cvss epss 0.02

    WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains…

  • CVE-2002-1980Dec 31, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in Volume Manager daemon (vold) of Sun Solaris 2.5.1 through 8 allows local users to execute arbitrary code via unknown attack vectors.

  • CVE-2002-1981Dec 31, 2002
    risk 0.00cvss epss 0.05

    Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.

  • CVE-2002-1982Dec 31, 2002
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.

  • CVE-2002-1983Dec 31, 2002
    risk 0.03cvss epss 0.01

    The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.

  • CVE-2002-1984Dec 31, 2002
    risk 0.01cvss epss 0.09

    Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".

  • CVE-2002-1985Dec 31, 2002
    risk 0.00cvss epss 0.02

    iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long "MAIL FROM" command, possibly triggering a buffer overflow.

  • CVE-2002-1986Dec 31, 2002
    risk 0.04cvss epss 0.07

    Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").

  • CVE-2002-1987Dec 31, 2002
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in view_source.jsp in Resin 2.1.2 allows remote attackers to read arbitrary files via a "\.." (backslash dot dot).

  • CVE-2002-1988Dec 31, 2002
    risk 0.00cvss epss 0.02

    Resin 2.1.1 allows remote attackers to cause a denial of service (memory consumption and hang) via a URL with long variables for non-existent resources.

  • CVE-2002-1989Dec 31, 2002
    risk 0.00cvss epss 0.01

    Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp.

  • CVE-2002-1990Dec 31, 2002
    risk 0.00cvss epss 0.02

    Resin 2.0.5 through 2.1.2 allows remote attackers to reveal physical path information via a URL request for the example Java class file HelloServlet.

  • CVE-2002-1991Dec 31, 2002
    risk 0.04cvss epss 0.07

    PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

  • CVE-2002-1992Dec 31, 2002
    risk 0.00cvss epss 0.02

    Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.

  • CVE-2002-1993Dec 31, 2002
    risk 0.04cvss epss 0.12

    webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.

  • CVE-2002-1994Dec 31, 2002
    risk 0.00cvss epss 0.02

    advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence.

  • CVE-2002-1995Dec 31, 2002
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn parameter.

  • CVE-2002-1996Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.

  • CVE-2002-1997Dec 31, 2002
    risk 0.00cvss epss 0.03

    ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.

  • CVE-2002-1998Dec 31, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to execute arbitrary commands via a long parameter to rtable_create (procedure 21).

  • CVE-2002-1999Dec 31, 2002
    risk 0.00cvss epss 0.03

    HP Praesidium Webproxy 1.0 running on HP-UX 11.04 VVOS could allow remote attackers to cause Webproxy to forward requests to the internal network via crafted HTTP requests.

  • CVE-2002-2000Dec 31, 2002
    risk 0.00cvss epss 0.00

    ACMS 4.3 and 4.4 in OpenVMS Alpha 7.2 and 7.3 does not properly use process privileges, which allows attackers to access data.

  • CVE-2002-2001Dec 31, 2002
    risk 0.00cvss epss 0.00

    jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2002-2002Dec 31, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in libc in Compaq Tru64 4.0F, 5.0, 5.1 and 5.1A allows attackers to execute arbitrary code via long (1) LANG and (2) LOCPATH environment variables.

  • CVE-2002-2003Dec 31, 2002
    risk 0.00cvss epss 0.01

    ypbind in Compaq Tru64 4.0F, 4.0G, 5.0A, 5.1 and 5.1A allows remote attackers to cause the process to core dump via certain network packets generated by nmap.

  • CVE-2002-2004Dec 31, 2002
    risk 0.00cvss epss 0.01

    portmapper in Compaq Tru64 4.0G and 5.0A allows remote attackers to cause a denial of service via a flood of packets.

  • CVE-2002-2005Dec 31, 2002
    risk 0.00cvss epss 0.02

    Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors.

  • CVE-2002-2006Dec 31, 2002
    risk 0.05cvss epss 0.31

    The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.

  • CVE-2002-2007Dec 31, 2002
    risk 0.06cvss epss 0.41

    The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3)…

  • CVE-2002-2008Dec 31, 2002
    risk 0.01cvss epss 0.07

    Apache Tomcat 4.0.3 for Windows allows remote attackers to obtain the web root path via an HTTP request for a resource that does not exist, such as lpt9, which leaks the information in an error message.

  • CVE-2002-2009Dec 31, 2002
    risk 0.01cvss epss 0.07

    Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3) </, and (4) %20/, which leaks the pathname in an error message.

  • CVE-2002-2010Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in htsearch.cgi in htdig (ht://Dig) 3.1.5, 3.1.6, and 3.2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

  • CVE-2002-2011Dec 31, 2002
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote attackers to inject arbitrary web script or HTML via the file parameter.

  • CVE-2002-2012Dec 31, 2002
    risk 0.00cvss epss 0.06

    Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.

  • CVE-2002-2013Dec 31, 2002
    risk 0.00cvss epss 0.02

    Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.

  • CVE-2002-2014Dec 31, 2002
    risk 0.00cvss epss 0.02

    Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.

  • CVE-2002-2015Dec 31, 2002
    risk 0.04cvss epss 0.09

    PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.