VYPR

CVEs

342,886 total · page 6743 of 6,858

  • CVE-2002-2277Dec 31, 2002
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL commands via the (1) $rech, (2) $BD_Tab_docs, (3) $BD_Tab_file, (4) $BD_Tab_liens, (5) $BD_Tab_faq, or (6) $chemin variables.

  • CVE-2002-2278Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to inject arbitrary web script or HTML via the (1) $App_Theme, (2) $Rub_Search, (3) $Rub_News, (4) $Rub_File, (5) $Rub_Liens, or (6) $Rub_Faq variables.

  • CVE-2002-2279Dec 31, 2002
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the bind function in config.inc of aldap 0.09 allows remote attackers to authenticate with Manager permissions.

  • CVE-2002-2280Dec 31, 2002
    risk 0.00cvss epss 0.00

    syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.

  • CVE-2002-2281Dec 31, 2002
    risk 0.04cvss epss 0.10

    Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler.

  • CVE-2002-2282Dec 31, 2002
    risk 0.00cvss epss 0.00

    McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs.

  • CVE-2002-2283Dec 31, 2002
    risk 0.00cvss epss 0.02

    Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users.

  • CVE-2002-2284Dec 31, 2002
    risk 0.00cvss epss 0.02

    Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.

  • CVE-2002-2285Dec 31, 2002
    risk 0.00cvss epss 0.02

    eTrust InoculateIT 6.0 with the "Incremental Scan" option enabled may certify that a file is free of viruses before the file has been completely downloaded, which allows remote attackers to bypass virus detection.

  • CVE-2002-2286Dec 31, 2002
    risk 0.00cvss epss 0.01

    The parse-get function in utils.c for apt-www-proxy 0.1 allows remote attackers to cause a denial of service (crash) via an empty HTTP request, which causes a null dereference.

  • CVE-2002-2287Dec 31, 2002
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

  • CVE-2002-2288Dec 31, 2002
    risk 0.03cvss epss 0.02

    Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.

  • CVE-2002-2289Dec 31, 2002
    risk 0.00cvss epss 0.01

    soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.

  • CVE-2002-2290Dec 31, 2002
    risk 0.00cvss epss 0.02

    Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.

  • CVE-2002-2291Dec 31, 2002
    risk 0.00cvss epss 0.02

    Calisto Internet Talker 0.04 and earlier allows remote attackers to cause a denial of service (hang) via a long request, possibly triggering a buffer overflow.

  • CVE-2002-2292Dec 31, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Remote Console Applet in Halycon Software iASP 1.0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request to port 9095.

  • CVE-2002-2293Dec 31, 2002
    risk 0.00cvss epss 0.00

    Webshots Desktop screensaver allows local users to bypass the password on the screensaver by pressing CTRL-ALT-DELETE and (1) hitting the cancel button or (2) killing the screensaver from the task manager.

  • CVE-2002-2294Dec 31, 2002
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed…

  • CVE-2002-2295Dec 31, 2002
    risk 0.04cvss epss 0.07

    Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an off-by-one buffer overflow, or (2) a long method name in an…

  • CVE-2002-2296Dec 31, 2002
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.

  • CVE-2002-2297Dec 31, 2002
    risk 0.00cvss epss 0.01

    PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

  • CVE-2002-2298Dec 31, 2002
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

  • CVE-2002-2299Dec 31, 2002
    risk 0.00cvss epss 0.01

    PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter.

  • CVE-2002-2300Dec 31, 2002
    risk 0.03cvss epss 0.05

    Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial of service (crash) via a long CEL command.

  • CVE-2002-2301Dec 31, 2002
    risk 0.00cvss epss 0.00

    Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database.

  • CVE-2002-2302Dec 31, 2002
    risk 0.00cvss epss 0.01

    3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form field.

  • CVE-2002-2303Dec 31, 2002
    risk 0.00cvss epss 0.01

    3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart prices by using the Javascript to decrypt the cookie that contains the data.

  • CVE-2002-2304Dec 31, 2002
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter.

  • CVE-2002-2305Dec 31, 2002
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands via the (1) agentname or (2) agentpassword parameter.

  • CVE-2002-2306Dec 31, 2002
    risk 0.03cvss epss 0.03

    Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages.

  • CVE-2002-2307Dec 31, 2002
    risk 0.00cvss epss 0.02

    The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20.

  • CVE-2002-2308Dec 31, 2002
    risk 0.00cvss epss 0.01

    Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself.

  • CVE-2002-2309Dec 31, 2002
    risk 0.03cvss epss 0.04

    php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.

  • CVE-2002-2310Dec 31, 2002
    risk 0.00cvss epss 0.01

    ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords.

  • CVE-2002-2311Dec 31, 2002
    risk 0.01cvss epss 0.10

    Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the…

  • CVE-2002-2312Dec 31, 2002
    risk 0.03cvss epss 0.02

    Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage.

  • CVE-2002-2313Dec 31, 2002
    risk 0.00cvss epss 0.01

    Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedded .mhtml file with ActiveX controls that execute a second embedded program,…

  • CVE-2002-2314Dec 31, 2002
    risk 0.04cvss epss 0.09

    Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.

  • CVE-2002-2315Dec 31, 2002
    risk 0.04cvss epss 0.10

    Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router.

  • CVE-2002-2316Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network information by…

  • CVE-2002-2317Dec 31, 2002
    risk 0.00cvss epss 0.02

    Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumption) via an unknown method.

  • CVE-2002-2318Dec 31, 2002
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.

  • CVE-2002-2319Dec 31, 2002
    risk 0.03cvss epss 0.02

    Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3.

  • CVE-2002-2320Dec 31, 2002
    risk 0.00cvss epss 0.01

    MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.

  • CVE-2002-2321Dec 31, 2002
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

  • CVE-2002-2322Dec 31, 2002
    risk 0.00cvss epss 0.01

    Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.

  • CVE-2002-2323HigDec 31, 2002
    risk 0.49cvss 7.5epss 0.02

    Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.

  • CVE-2002-2324Dec 31, 2002
    risk 0.00cvss epss 0.02

    The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted files and modify…

  • CVE-2002-2325Dec 31, 2002
    risk 0.03cvss epss 0.03

    The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44, allows remote attackers to cause a denial of service (client crash) via a MIME-encoded email with Content-Type header containing an empty boundary field.

  • CVE-2002-2326Dec 31, 2002
    risk 0.00cvss epss 0.01

    The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext when connecting to Mac.com, which could allow remote attackers to obtain passwords by sniffing network traffic.