VYPR

CVEs

342,869 total · page 6746 of 6,858

  • CVE-2002-1260Dec 23, 2002
    risk 0.01cvss epss 0.15

    The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet.

  • CVE-2002-1296Dec 23, 2002
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

  • CVE-2002-1325Dec 23, 2002
    risk 0.01cvss epss 0.14

    Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."

  • CVE-2002-1345Dec 23, 2002
    risk 0.00cvss epss 0.03

    Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.

  • CVE-2002-1350Dec 23, 2002
    risk 0.00cvss epss 0.02

    The BGP decoding routines in tcpdump 3.6.x before 3.7 do not properly copy data, which allows remote attackers to cause a denial of service (application crash).

  • CVE-2002-1355Dec 23, 2002
    risk 0.00cvss epss 0.02

    Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages.

  • CVE-2002-1356Dec 23, 2002
    risk 0.00cvss epss 0.03

    Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages.

  • CVE-2002-1357Dec 23, 2002
    risk 0.01cvss epss 0.10

    Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

  • CVE-2002-1358Dec 23, 2002
    risk 0.00cvss epss 0.06

    Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

  • CVE-2002-1359Dec 23, 2002
    risk 0.09cvss epss 0.80

    Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.

  • CVE-2002-1360Dec 23, 2002
    risk 0.00cvss epss 0.06

    Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the…

  • CVE-2002-1361Dec 23, 2002
    risk 0.04cvss epss 0.12

    overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.

  • CVE-2002-1362Dec 23, 2002
    risk 0.00cvss epss 0.02

    mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.

  • CVE-2002-1364Dec 23, 2002
    risk 0.03cvss epss 0.02

    Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.

  • CVE-2002-1365Dec 23, 2002
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in Fetchmail 6.1.3 and earlier does not account for the "@" character when determining buffer lengths for local addresses, which allows remote attackers to execute arbitrary code via a header with a large number of local addresses.

  • CVE-2002-1373Dec 23, 2002
    risk 0.00cvss epss 0.04

    Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.

  • CVE-2002-1374Dec 23, 2002
    risk 0.05cvss epss 0.20

    The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real…

  • CVE-2002-1375Dec 23, 2002
    risk 0.05cvss epss 0.24

    The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.

  • CVE-2002-1376Dec 23, 2002
    risk 0.01cvss epss 0.07

    libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.

  • CVE-2002-1377Dec 23, 2002
    risk 0.00cvss epss 0.00

    vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.

  • CVE-2002-1380Dec 23, 2002
    risk 0.03cvss epss 0.01

    Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface.

  • CVE-2002-1381Dec 23, 2002
    risk 0.03cvss epss 0.02

    Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.

  • CVE-2002-1382Dec 23, 2002
    risk 0.00cvss epss 0.03

    Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846.

  • CVE-2002-1643Dec 19, 2002
    risk 0.09cvss epss 0.74

    Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET…

  • CVE-2002-1158Dec 18, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.

  • CVE-2002-1159Dec 18, 2002
    risk 0.00cvss epss 0.02

    Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.

  • CVE-2002-1255Dec 18, 2002
    risk 0.01cvss epss 0.14

    Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."

  • CVE-2002-1262Dec 18, 2002
    risk 0.01cvss epss 0.12

    Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files.

  • CVE-2002-1338Dec 18, 2002
    risk 0.02cvss epss 0.23

    The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.

  • CVE-2002-1339Dec 18, 2002
    risk 0.01cvss epss 0.12

    The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.

  • CVE-2002-1340Dec 18, 2002
    risk 0.01cvss epss 0.12

    The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception.

  • CVE-2002-1341Dec 18, 2002
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.

  • CVE-2002-1342Dec 18, 2002
    risk 0.00cvss epss 0.02

    Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.

  • CVE-2002-1344Dec 18, 2002
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.

  • CVE-2002-1347CriDec 18, 2002
    risk 0.64cvss 9.8epss 0.07

    Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication…

  • CVE-2002-1349Dec 18, 2002
    risk 0.03cvss epss 0.01

    Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).

  • CVE-2002-1354Dec 18, 2002
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.

  • CVE-2002-1183Dec 11, 2002
    risk 0.05cvss epss 0.19

    Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).

  • CVE-2002-1185Dec 11, 2002
    risk 0.02cvss epss 0.21

    Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka…

  • CVE-2002-1186Dec 11, 2002
    risk 0.02cvss epss 0.19

    Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka…

  • CVE-2002-1187Dec 11, 2002
    risk 0.04cvss epss 0.14

    Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the or element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the…

  • CVE-2002-1188Dec 11, 2002
    risk 0.01cvss epss 0.12

    Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet…

  • CVE-2002-1254Dec 11, 2002
    risk 0.07cvss epss 0.51

    Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."

  • CVE-2002-1266Dec 11, 2002
    risk 0.00cvss epss 0.00

    Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File."

  • CVE-2002-1267Dec 11, 2002
    risk 0.00cvss epss 0.02

    Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing Web Administration utility, aka "CUPS Printing Web Administration is Remotely Accessible."

  • CVE-2002-1268Dec 11, 2002
    risk 0.00cvss epss 0.00

    Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD."

  • CVE-2002-1269Dec 11, 2002
    risk 0.00cvss epss 0.00

    Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem.

  • CVE-2002-1270Dec 11, 2002
    risk 0.00cvss epss 0.00

    Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call.

  • CVE-2002-1272Dec 11, 2002
    risk 0.00cvss epss 0.05

    Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remote attackers to gain administrative privileges.

  • CVE-2002-1317Dec 11, 2002
    risk 0.05cvss epss 0.24

    Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.