| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2002-0476 | 0.00 | — | 0.02 | Aug 12, 2002 | Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand. | |||
| CVE-2002-0477 | 0.00 | — | 0.02 | Aug 12, 2002 | Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand. | |||
| CVE-2002-0478 | 0.00 | — | 0.02 | Aug 12, 2002 | The default configuration of Foundry Networks EdgeIron 4802F allows remote attackers to modify sensitive information via arbitrary SNMP community strings. | |||
| CVE-2002-0479 | 0.00 | — | 0.00 | Aug 12, 2002 | Gravity Storm Service Pack Manager 2000 creates a hidden share (SPM2000c$) mapped to the C drive, which may allow local users to bypass access restrictions on certain directories in the C drive, such as system32, by accessing them through the hidden share. | |||
| CVE-2002-0480 | 0.00 | — | 0.03 | Aug 12, 2002 | ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow… | |||
| CVE-2002-0481 | 0.01 | — | 0.10 | Aug 12, 2002 | An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers… | |||
| CVE-2002-0482 | 0.00 | — | 0.02 | Aug 12, 2002 | Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request. | |||
| CVE-2002-0483 | 0.04 | — | 0.08 | Aug 12, 2002 | index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname. | |||
| CVE-2002-0484 | 0.04 | — | 0.10 | Aug 12, 2002 | move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system. | |||
| CVE-2002-0485 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2002 | Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients. | ||
| CVE-2002-0486 | 0.03 | — | 0.01 | Aug 12, 2002 | Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges. | |||
| CVE-2002-0487 | 0.00 | — | 0.00 | Aug 12, 2002 | Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache. | |||
| CVE-2002-0488 | 0.00 | — | 0.06 | Aug 12, 2002 | Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter. | |||
| CVE-2002-0489 | 0.00 | — | 0.06 | Aug 12, 2002 | Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters. | |||
| CVE-2002-0490 | 0.00 | — | 0.03 | Aug 12, 2002 | Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php. | |||
| CVE-2002-0491 | 0.00 | — | 0.03 | Aug 12, 2002 | admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileges by setting the admin cookie to an arbitrary value. | |||
| CVE-2002-0492 | 0.03 | — | 0.02 | Aug 12, 2002 | dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter. | |||
| CVE-2002-0493 | 0.00 | — | 0.04 | Aug 12, 2002 | Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions. | |||
| CVE-2002-0494 | 0.00 | — | 0.02 | Aug 12, 2002 | Cross-site scripting vulnerability in WebSight Directory System 0.1 allows remote attackers to execute arbitrary Javascript and gain access to the WebSight administrator via a new link submission containing the script in a website name. | |||
| CVE-2002-0495 | 0.04 | — | 0.13 | Aug 12, 2002 | csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi. | |||
| CVE-2002-0496 | 0.00 | — | 0.02 | Aug 12, 2002 | The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002. | |||
| CVE-2002-0497 | 0.00 | — | 0.01 | Aug 12, 2002 | Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable. | |||
| CVE-2002-0498 | 0.00 | — | 0.00 | Aug 12, 2002 | Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users. | |||
| CVE-2002-0499 | 0.03 | — | 0.01 | Aug 12, 2002 | The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories. | |||
| CVE-2002-0500 | 0.01 | — | 0.15 | Aug 12, 2002 | Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size. | |||
| CVE-2002-0501 | 0.00 | — | 0.01 | Aug 12, 2002 | Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages. | |||
| CVE-2002-0502 | 0.03 | — | 0.04 | Aug 12, 2002 | Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page. | |||
| CVE-2002-0503 | 0.00 | — | 0.02 | Aug 12, 2002 | Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter. | |||
| CVE-2002-0504 | 0.04 | — | 0.08 | Aug 12, 2002 | Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp. | |||
| CVE-2002-0505 | 0.00 | — | 0.02 | Aug 12, 2002 | Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords. | |||
| CVE-2002-0506 | 0.00 | — | 0.00 | Aug 12, 2002 | Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt. | |||
| CVE-2002-0507 | 0.00 | — | 0.02 | Aug 12, 2002 | An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually… | |||
| CVE-2002-0508 | 0.00 | — | 0.05 | Aug 12, 2002 | wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog. | |||
| CVE-2002-0509 | 0.00 | — | 0.03 | Aug 12, 2002 | Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521. | |||
| CVE-2002-0510 | 0.00 | — | 0.02 | Aug 12, 2002 | The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux. | |||
| CVE-2002-0511 | 0.00 | — | 0.02 | Aug 12, 2002 | The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which could make it easier for remote attackers to bypass applications that restrict… | |||
| CVE-2002-0512 | 0.00 | — | 0.00 | Aug 12, 2002 | startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries. | |||
| CVE-2002-0513 | 0.00 | — | 0.05 | Aug 12, 2002 | The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator. | |||
| CVE-2002-0514 | 0.00 | — | 0.02 | Aug 12, 2002 | PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL. | |||
| CVE-2002-0515 | 0.00 | — | 0.02 | Aug 12, 2002 | IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs. | |||
| CVE-2002-0516 | 0.04 | — | 0.11 | Aug 12, 2002 | SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie. | |||
| CVE-2002-0517 | 0.00 | — | 0.00 | Aug 12, 2002 | Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm. | |||
| CVE-2002-0518 | 0.00 | — | 0.02 | Aug 12, 2002 | The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced for the socket's TCP options,… | |||
| CVE-2002-0520 | 0.00 | — | 0.02 | Aug 12, 2002 | Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag. | |||
| CVE-2002-0521 | 0.00 | — | 0.02 | Aug 12, 2002 | Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.asp, (2) the message parameter in Post.asp, or (3) a web site URL in profile.asp. | |||
| CVE-2002-0522 | 0.00 | — | 0.02 | Aug 12, 2002 | ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie. | |||
| CVE-2002-0523 | 0.00 | — | 0.02 | Aug 12, 2002 | ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie. | |||
| CVE-2002-0524 | 0.00 | — | 0.02 | Aug 12, 2002 | ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, which leak the pathname in an error message. | |||
| CVE-2002-0525 | 0.03 | — | 0.04 | Aug 12, 2002 | Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses. | |||
| CVE-2002-0526 | 0.00 | — | 0.01 | Aug 12, 2002 | Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls. |
- CVE-2002-0476Aug 12, 2002risk 0.00cvss —epss 0.02
Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.
- CVE-2002-0477Aug 12, 2002risk 0.00cvss —epss 0.02
Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.
- CVE-2002-0478Aug 12, 2002risk 0.00cvss —epss 0.02
The default configuration of Foundry Networks EdgeIron 4802F allows remote attackers to modify sensitive information via arbitrary SNMP community strings.
- CVE-2002-0479Aug 12, 2002risk 0.00cvss —epss 0.00
Gravity Storm Service Pack Manager 2000 creates a hidden share (SPM2000c$) mapped to the C drive, which may allow local users to bypass access restrictions on certain directories in the C drive, such as system32, by accessing them through the hidden share.
- CVE-2002-0480Aug 12, 2002risk 0.00cvss —epss 0.03
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow…
- CVE-2002-0481Aug 12, 2002risk 0.01cvss —epss 0.10
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers…
- CVE-2002-0482Aug 12, 2002risk 0.00cvss —epss 0.02
Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.
- CVE-2002-0483Aug 12, 2002risk 0.04cvss —epss 0.08
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.
- CVE-2002-0484Aug 12, 2002risk 0.04cvss —epss 0.10
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload files to unintended locations on the system.
- risk 0.49cvss 7.5epss 0.01
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.
- CVE-2002-0486Aug 12, 2002risk 0.03cvss —epss 0.01
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.
- CVE-2002-0487Aug 12, 2002risk 0.00cvss —epss 0.00
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache.
- CVE-2002-0488Aug 12, 2002risk 0.00cvss —epss 0.06
Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter.
- CVE-2002-0489Aug 12, 2002risk 0.00cvss —epss 0.06
Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters.
- CVE-2002-0490Aug 12, 2002risk 0.00cvss —epss 0.03
Instant Web Mail before 0.60 does not properly filter CR/LF sequences, which allows remote attackers to (1) execute arbitrary POP commands via the id parameter in message.php, or (2) modify certain mail message headers via numerous parameters in write.php.
- CVE-2002-0491Aug 12, 2002risk 0.00cvss —epss 0.03
admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileges by setting the admin cookie to an arbitrary value.
- CVE-2002-0492Aug 12, 2002risk 0.03cvss —epss 0.02
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
- CVE-2002-0493Aug 12, 2002risk 0.00cvss —epss 0.04
Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
- CVE-2002-0494Aug 12, 2002risk 0.00cvss —epss 0.02
Cross-site scripting vulnerability in WebSight Directory System 0.1 allows remote attackers to execute arbitrary Javascript and gain access to the WebSight administrator via a new link submission containing the script in a website name.
- CVE-2002-0495Aug 12, 2002risk 0.04cvss —epss 0.13
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.
- CVE-2002-0496Aug 12, 2002risk 0.00cvss —epss 0.02
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002.
- CVE-2002-0497Aug 12, 2002risk 0.00cvss —epss 0.01
Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable.
- CVE-2002-0498Aug 12, 2002risk 0.00cvss —epss 0.00
Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users.
- CVE-2002-0499Aug 12, 2002risk 0.03cvss —epss 0.01
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.
- CVE-2002-0500Aug 12, 2002risk 0.01cvss —epss 0.15
Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.
- CVE-2002-0501Aug 12, 2002risk 0.00cvss —epss 0.01
Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.
- CVE-2002-0502Aug 12, 2002risk 0.03cvss —epss 0.04
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.
- CVE-2002-0503Aug 12, 2002risk 0.00cvss —epss 0.02
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
- CVE-2002-0504Aug 12, 2002risk 0.04cvss —epss 0.08
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.
- CVE-2002-0505Aug 12, 2002risk 0.00cvss —epss 0.02
Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.
- CVE-2002-0506Aug 12, 2002risk 0.00cvss —epss 0.00
Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.
- CVE-2002-0507Aug 12, 2002risk 0.00cvss —epss 0.02
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually…
- CVE-2002-0508Aug 12, 2002risk 0.00cvss —epss 0.05
wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.
- CVE-2002-0509Aug 12, 2002risk 0.00cvss —epss 0.03
Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.
- CVE-2002-0510Aug 12, 2002risk 0.00cvss —epss 0.02
The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.
- CVE-2002-0511Aug 12, 2002risk 0.00cvss —epss 0.02
The default configuration of Name Service Cache Daemon (nscd) in Caldera OpenLinux 3.1 and 3.1.1 uses cached PTR records instead of consulting the authoritative DNS server for the A record, which could make it easier for remote attackers to bypass applications that restrict…
- CVE-2002-0512Aug 12, 2002risk 0.00cvss —epss 0.00
startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries.
- CVE-2002-0513Aug 12, 2002risk 0.00cvss —epss 0.05
The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
- CVE-2002-0514Aug 12, 2002risk 0.00cvss —epss 0.02
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.
- CVE-2002-0515Aug 12, 2002risk 0.00cvss —epss 0.02
IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.
- CVE-2002-0516Aug 12, 2002risk 0.04cvss —epss 0.11
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a cookie.
- CVE-2002-0517Aug 12, 2002risk 0.00cvss —epss 0.00
Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.
- CVE-2002-0518Aug 12, 2002risk 0.00cvss —epss 0.02
The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced for the socket's TCP options,…
- CVE-2002-0520Aug 12, 2002risk 0.00cvss —epss 0.02
Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag.
- CVE-2002-0521Aug 12, 2002risk 0.00cvss —epss 0.02
Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.asp, (2) the message parameter in Post.asp, or (3) a web site URL in profile.asp.
- CVE-2002-0522Aug 12, 2002risk 0.00cvss —epss 0.02
ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie.
- CVE-2002-0523Aug 12, 2002risk 0.00cvss —epss 0.02
ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie.
- CVE-2002-0524Aug 12, 2002risk 0.00cvss —epss 0.02
ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, which leak the pathname in an error message.
- CVE-2002-0525Aug 12, 2002risk 0.03cvss —epss 0.04
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.
- CVE-2002-0526Aug 12, 2002risk 0.00cvss —epss 0.01
Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls.