VYPR

CVEs

342,886 total · page 6742 of 6,858

  • CVE-2002-2227Dec 31, 2002
    risk 0.00cvss epss 0.03

    Buffer underflow in ssldump 0.9b2 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted SSLv2 challenge value.

  • CVE-2002-2228Dec 31, 2002
    risk 0.00cvss epss 0.01

    MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner.

  • CVE-2002-2229Dec 31, 2002
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request.

  • CVE-2002-2230Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via a private message with a javascript: URL in the IMG tag, in which the URL ends in a ".gif" or ".jpg" string, a variant of CVE-2002-0328.

  • CVE-2002-2231Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL in a photo URL or (2) an X-Forwarded-For: header.

  • CVE-2002-2232Dec 31, 2002
    risk 0.03cvss epss 0.05

    Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.

  • CVE-2002-2233Dec 31, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

  • CVE-2002-2234Dec 31, 2002
    risk 0.00cvss epss 0.01

    NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests.

  • CVE-2002-2235Dec 31, 2002
    risk 0.03cvss epss 0.02

    member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.

  • CVE-2002-2236Dec 31, 2002
    risk 0.00cvss epss 0.05

    Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code.

  • CVE-2002-2237Dec 31, 2002
    risk 0.00cvss epss 0.02

    tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux.

  • CVE-2002-2238Dec 31, 2002
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.

  • CVE-2002-2239Dec 31, 2002
    risk 0.00cvss epss 0.02

    The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet.

  • CVE-2002-2240Dec 31, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request.

  • CVE-2002-2241Dec 31, 2002
    risk 0.00cvss epss 0.02

    Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request.

  • CVE-2002-2242Dec 31, 2002
    risk 0.00cvss epss 0.01

    The Apple Package Manager in KisMAC 0.02a and earlier modifies file permissions of sensitive files after installation, which could allow attackers to conduct unauthorized activities on those files.

  • CVE-2002-2243Dec 31, 2002
    risk 0.00cvss epss 0.01

    Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it.

  • CVE-2002-2244Dec 31, 2002
    risk 0.00cvss epss 0.00

    Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle.

  • CVE-2002-2245Dec 31, 2002
    risk 0.00cvss epss 0.01

    ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.

  • CVE-2002-2246Dec 31, 2002
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page.

  • CVE-2002-2247Dec 31, 2002
    risk 0.03cvss epss 0.03

    The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.

  • CVE-2002-2248Dec 31, 2002
    risk 0.00cvss epss 0.06

    Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.

  • CVE-2002-2249Dec 31, 2002
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php.

  • CVE-2002-2250Dec 31, 2002
    risk 0.01cvss epss 0.08

    Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter to the xp_freedll extended stored procedure or (2) a long database name argument to the DBCC CHECKVERIFY function.

  • CVE-2002-2251Dec 31, 2002
    risk 0.04cvss epss 0.07

    Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a long argument.

  • CVE-2002-2252Dec 31, 2002
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter.

  • CVE-2002-2253Dec 31, 2002
    risk 0.01cvss epss 0.07

    Multiple buffer overflows in Cyrus Sieve / libSieve 2.1.2 and earlier allow remote attackers to execute arbitrary code via (1) a long header name, (2) a long IMAP flag, or (3) a script that generates a large number of errors that overflow the resulting error string.

  • CVE-2002-2254Dec 31, 2002
    risk 0.00cvss epss 0.00

    The experimental IP packet queuing feature in Netfilter / IPTables in Linux kernel 2.4 up to 2.4.19 and 2.5 up to 2.5.31, when a privileged process exits and network traffic is not being queued, may allow a later process with the same Process ID (PID) to access certain network…

  • CVE-2002-2255Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.

  • CVE-2002-2256Dec 31, 2002
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in pWins Webserver 0.2.5 and earlier allows remote attackers to read arbitrary files via Unicode characters.

  • CVE-2002-2257Dec 31, 2002
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in the parse_field function in cgi_lib.c for LIBCGI 1.0.2 and 1.0.3 allows remote attackers to execute arbitrary code via a long argument.

  • CVE-2002-2258Dec 31, 2002
    risk 0.03cvss epss 0.03

    Moby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large integer or (2) non-numeric value in the Content-Length header, which causes an access violation after a failed atoi function call.

  • CVE-2002-2259Dec 31, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors.

  • CVE-2002-2260Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the quips feature in Mozilla Bugzilla 2.10 through 2.17 allows remote attackers to inject arbitrary web script or HTML via the "show all quips" page.

  • CVE-2002-2261Dec 31, 2002
    risk 0.00cvss epss 0.02

    Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname.

  • CVE-2002-2262Dec 31, 2002
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.

  • CVE-2002-2263Dec 31, 2002
    risk 0.00cvss epss 0.00

    The installation program for HP-UX Visualize Conference B.11.00.11 running on HP-UX 11.00 and 11.11 installs /etc/dt and its subdirecties with insecure permissions, which allows local users to read or write arbitrary files.

  • CVE-2002-2264Dec 31, 2002
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might be the same issue as CVE-2002-2185, but there are insufficient details to be…

  • CVE-2002-2265Dec 31, 2002
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors.

  • CVE-2002-2266Dec 31, 2002
    risk 0.00cvss epss 0.01

    NetScreen ScreenOS 2.8 through 4.0, when forwarding H.323 or Netmeeting traffic, allows remote attackers to cause a denial of service (firewall session table consumption) by establishing multiple half-open H.323 sessions, which are not cleaned up on garbage removal and do not…

  • CVE-2002-2267Dec 31, 2002
    risk 0.00cvss epss 0.00

    bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file.

  • CVE-2002-2268Dec 31, 2002
    risk 0.07cvss epss 0.53

    Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.

  • CVE-2002-2269Dec 31, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

  • CVE-2002-2270Dec 31, 2002
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.

  • CVE-2002-2271Dec 31, 2002
    risk 0.00cvss epss 0.01

    Buffer overflow in BigFun 1.51b IRC client, when the Direct Client Connection (DCC) option is used, allows remote attackers to cause a denial of service (crash) via a long string.

  • CVE-2002-2272Dec 31, 2002
    risk 0.04cvss epss 0.10

    Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.

  • CVE-2002-2273Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows remote attackers to inject arbitrary web script or HTML via the URL.

  • CVE-2002-2274Dec 31, 2002
    risk 0.00cvss epss 0.00

    akfingerd 0.5 allows local users to read arbitrary files as the akfingerd user (nobody) via a symlink attack on the .plan file.

  • CVE-2002-2275Dec 31, 2002
    risk 0.00cvss epss 0.00

    Fortres 101 4.1 allows local users to bypass Fortres by pressing the Windows and "F" key together for 30 seconds, which opens multiple windows and eventually causes explorer.exe to crash, which then opens an unrestricted explorer.exe.

  • CVE-2002-2276Dec 31, 2002
    risk 0.00cvss epss 0.01

    Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message.