VYPR

CVEs

342,869 total · page 6748 of 6,858

  • CVE-2002-0869Nov 12, 2002
    risk 0.02cvss epss 0.24

    Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege…

  • CVE-2002-1180Nov 12, 2002
    risk 0.01cvss epss 0.09

    A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."

  • CVE-2002-1181Nov 12, 2002
    risk 0.03cvss epss 0.39

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or…

  • CVE-2002-1182Nov 12, 2002
    risk 0.03cvss epss 0.36

    IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.

  • CVE-2002-1184Nov 12, 2002
    risk 0.00cvss epss 0.02

    The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other…

  • CVE-2002-1211Nov 12, 2002
    risk 0.03cvss epss 0.03

    Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.

  • CVE-2002-1236Nov 12, 2002
    risk 0.04cvss epss 0.07

    The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.

  • CVE-2002-1238Nov 12, 2002
    risk 0.04cvss epss 0.07

    Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.

  • CVE-2002-1239Nov 12, 2002
    risk 0.03cvss epss 0.01

    QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.

  • CVE-2002-1242Nov 12, 2002
    risk 0.03cvss epss 0.04

    SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.

  • CVE-2002-1244Nov 12, 2002
    risk 0.00cvss epss 0.03

    Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.

  • CVE-2002-1245Nov 12, 2002
    risk 0.00cvss epss 0.00

    Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program.

  • CVE-2002-1248Nov 12, 2002
    risk 0.03cvss epss 0.03

    Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) via a GET request for a "%" URI.

  • CVE-2002-1250Nov 12, 2002
    risk 0.03cvss epss 0.01

    Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument.

  • CVE-2002-1251Nov 12, 2002
    risk 0.00cvss epss 0.06

    Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message.

  • CVE-2002-1253Nov 12, 2002
    risk 0.00cvss epss 0.01

    Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.

  • CVE-2002-1264Nov 12, 2002
    risk 0.01cvss epss 0.08

    Buffer overflow in Oracle iSQL*Plus web application of the Oracle 9 database server allows remote attackers to execute arbitrary code via a long USERID parameter in the isqlplus URL.

  • CVE-2002-1265Nov 12, 2002
    risk 0.00cvss epss 0.03

    The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).

  • CVE-2002-1271Nov 12, 2002
    risk 0.00cvss epss 0.04

    The Mail::Mailer Perl module in the perl-MailTools package 1.47 and earlier uses mailx as the default mailer, which allows remote attackers to execute arbitrary commands by inserting them into the mail body, which is then processed by mailx.

  • CVE-2002-1275Nov 12, 2002
    risk 0.04cvss epss 0.09

    Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."

  • CVE-2002-1277Nov 12, 2002
    risk 0.00cvss epss 0.05

    Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer.

  • CVE-2002-1278Nov 12, 2002
    risk 0.00cvss epss 0.02

    The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a way that configures Sendmail to run as an open mail relay, which allows remote…

  • CVE-2002-1585Nov 8, 2002
    risk 0.00cvss epss 0.02

    Unknown vulnerability in Solaris 8 for Intel and Solaris 8 and 9 for SPARC allows remote attackers to cause a denial of service via certain packets that cause some network interfaces to stop responding to TCP traffic.

  • CVE-2002-0386Nov 4, 2002
    risk 0.05cvss epss 0.22

    The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked…

  • CVE-2002-0666Nov 4, 2002
    risk 0.00cvss epss 0.02

    IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in…

  • CVE-2002-1157Nov 4, 2002
    risk 0.01cvss epss 0.10

    Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is…

  • CVE-2002-1167Nov 4, 2002
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

  • CVE-2002-1168Nov 4, 2002
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the…

  • CVE-2002-1169Nov 4, 2002
    risk 0.04cvss epss 0.07

    IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.

  • CVE-2002-1209Nov 4, 2002
    risk 0.04cvss epss 0.13

    Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.

  • CVE-2002-1230Nov 4, 2002
    risk 0.03cvss epss 0.02

    NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw…

  • CVE-2002-1231Nov 4, 2002
    risk 0.00cvss epss 0.00

    SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc.

  • CVE-2002-1232Nov 4, 2002
    risk 0.00cvss epss 0.03

    Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.

  • CVE-2002-1233Nov 4, 2002
    risk 0.00cvss epss 0.01

    A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on temporary files when the…

  • CVE-2002-1235Nov 4, 2002
    risk 0.01cvss epss 0.15

    The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with…

  • CVE-2002-1590Oct 29, 2002
    risk 0.00cvss epss 0.00

    The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges…

  • CVE-2002-0836Oct 28, 2002
    risk 0.01cvss epss 0.08

    dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.

  • CVE-2002-0990Oct 28, 2002
    risk 0.00cvss epss 0.02

    The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple connection requests to…

  • CVE-2002-1118Oct 28, 2002
    risk 0.00cvss epss 0.03

    TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.

  • CVE-2002-1145Oct 28, 2002
    risk 0.01cvss epss 0.08

    The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is…

  • CVE-2002-1179Oct 28, 2002
    risk 0.05cvss epss 0.20

    Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.

  • CVE-2002-1190Oct 28, 2002
    risk 0.00cvss epss 0.02

    Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.

  • CVE-2002-1191Oct 28, 2002
    risk 0.00cvss epss 0.02

    The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.

  • CVE-2002-1192Oct 28, 2002
    risk 0.03cvss epss 0.01

    Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.

  • CVE-2002-1193Oct 28, 2002
    risk 0.00cvss epss 0.00

    tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.

  • CVE-2002-1194Oct 28, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.

  • CVE-2002-1195Oct 28, 2002
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability (XSS) in the PHP interface for ht://Check 1.1 allows remote web servers to insert arbitrary HTML, including script, via a web page.

  • CVE-2002-1196Oct 28, 2002
    risk 0.00cvss epss 0.02

    editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of…

  • CVE-2002-1197Oct 28, 2002
    risk 0.00cvss epss 0.02

    bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.

  • CVE-2002-1198Oct 28, 2002
    risk 0.00cvss epss 0.01

    Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to execute arbitrary SQL via a SQL injection attack.