| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2002-0527 | 0.00 | — | 0.02 | Aug 12, 2002 | Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO forwards a packet with bad IP options. | |||
| CVE-2002-0528 | 0.00 | — | 0.03 | Aug 12, 2002 | Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules. | |||
| CVE-2002-0529 | 0.00 | — | 0.00 | Aug 12, 2002 | HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain privileges of other Photosmart users by replacing hp_imaging_connectivity with a… | |||
| CVE-2002-0530 | 0.00 | — | 0.01 | Aug 12, 2002 | Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter. | |||
| CVE-2002-0531 | 0.00 | — | 0.04 | Aug 12, 2002 | Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter. | |||
| CVE-2002-0532 | 0.00 | — | 0.00 | Aug 12, 2002 | EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters. | |||
| CVE-2002-0533 | 0.00 | — | 0.02 | Aug 12, 2002 | phpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags. | |||
| CVE-2002-0534 | 0.00 | — | 0.03 | Aug 12, 2002 | PostBoard 2.0.1 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags. | |||
| CVE-2002-0616 | 0.01 | — | 0.10 | Aug 12, 2002 | The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability." | |||
| CVE-2002-0617 | 0.01 | — | 0.11 | Aug 12, 2002 | The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook… | |||
| CVE-2002-0618 | 0.01 | — | 0.14 | Aug 12, 2002 | The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution". | |||
| CVE-2002-0619 | 0.01 | — | 0.16 | Aug 12, 2002 | The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge… | |||
| CVE-2002-0638 | 0.00 | — | 0.01 | Aug 12, 2002 | setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file… | |||
| CVE-2002-0644 | 0.04 | — | 0.11 | Aug 12, 2002 | Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code. | |||
| CVE-2002-0645 | 0.00 | — | 0.04 | Aug 12, 2002 | SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands. | |||
| CVE-2002-0649 | 0.10 | — | 0.85 | Aug 12, 2002 | Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL… | |||
| CVE-2002-0650 | 0.01 | — | 0.18 | Aug 12, 2002 | The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two… | |||
| CVE-2002-0655 | 0.01 | — | 0.08 | Aug 12, 2002 | OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code. | |||
| CVE-2002-0656 | 0.10 | — | 0.90 | Aug 12, 2002 | Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3. | |||
| CVE-2002-0657 | 0.01 | — | 0.09 | Aug 12, 2002 | Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key. | |||
| CVE-2002-0658 | 0.03 | — | 0.01 | Aug 12, 2002 | OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack. | |||
| CVE-2002-0659 | 0.06 | — | 0.36 | Aug 12, 2002 | The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings. | |||
| CVE-2002-0660 | 0.00 | — | 0.03 | Aug 12, 2002 | Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728. | |||
| CVE-2002-0661 | 0.02 | — | 0.70 | Aug 12, 2002 | Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters. | |||
| CVE-2002-0684 | 0.00 | — | 0.06 | Aug 12, 2002 | Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname… | |||
| CVE-2002-0695 | 0.01 | — | 0.17 | Aug 12, 2002 | Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command. | |||
| CVE-2002-0697 | 0.01 | — | 0.18 | Aug 12, 2002 | Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials. | |||
| CVE-2002-0698 | 0.02 | — | 0.20 | Aug 12, 2002 | Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response. | |||
| CVE-2002-0700 | 0.01 | — | 0.08 | Aug 12, 2002 | Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function… | |||
| CVE-2002-0710 | 0.00 | — | 0.03 | Aug 12, 2002 | Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter. | |||
| CVE-2002-0718 | 0.00 | — | 0.06 | Aug 12, 2002 | Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function." | |||
| CVE-2002-0719 | 0.01 | — | 0.10 | Aug 12, 2002 | SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files. | |||
| CVE-2002-0728 | 0.00 | — | 0.02 | Aug 12, 2002 | Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk. | |||
| CVE-2002-0729 | 0.01 | — | 0.11 | Aug 12, 2002 | Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator. | |||
| CVE-2002-0730 | 0.04 | — | 0.07 | Aug 12, 2002 | Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage. | |||
| CVE-2002-0731 | 0.03 | — | 0.03 | Aug 12, 2002 | Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as respond.pl. | |||
| CVE-2002-0732 | 0.03 | — | 0.03 | Aug 12, 2002 | Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments. | |||
| CVE-2002-0733 | 0.04 | — | 0.08 | Aug 12, 2002 | Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message. | |||
| CVE-2002-0734 | 0.04 | — | 0.07 | Aug 12, 2002 | b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets the $b2inc variable to point to a malicious program stored on a remote server. | |||
| CVE-2002-0735 | 0.00 | — | 0.03 | Aug 12, 2002 | Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages. | |||
| CVE-2002-0736 | 0.03 | — | 0.32 | Aug 12, 2002 | Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank. | |||
| CVE-2002-0737 | 0.04 | — | 0.09 | Aug 12, 2002 | Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character. | |||
| CVE-2002-0738 | 0.00 | — | 0.03 | Aug 12, 2002 | MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into smaller pieces, (2) including the script in a SRC argument to an IMG tag, or (3)… | |||
| CVE-2002-0739 | 0.00 | — | 0.02 | Aug 12, 2002 | Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page. | |||
| CVE-2002-0740 | 0.03 | — | 0.01 | Aug 12, 2002 | Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument. | |||
| CVE-2002-0741 | 0.04 | — | 0.08 | Aug 12, 2002 | psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long password argument and quickly killing the connection, which is not properly terminated by psyBNC. | |||
| CVE-2002-0742 | 0.00 | — | 0.01 | Aug 12, 2002 | Buffer overflow in pioout on AIX 4.3.3. | |||
| CVE-2002-0743 | 0.00 | — | 0.01 | Aug 12, 2002 | mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow. | |||
| CVE-2002-0744 | 0.00 | — | 0.01 | Aug 12, 2002 | namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow. | |||
| CVE-2002-0745 | 0.00 | — | 0.01 | Aug 12, 2002 | Buffer overflow in uucp in AIX 4.3.3. |
- CVE-2002-0527Aug 12, 2002risk 0.00cvss —epss 0.02
Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO forwards a packet with bad IP options.
- CVE-2002-0528Aug 12, 2002risk 0.00cvss —epss 0.03
Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules.
- CVE-2002-0529Aug 12, 2002risk 0.00cvss —epss 0.00
HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain privileges of other Photosmart users by replacing hp_imaging_connectivity with a…
- CVE-2002-0530Aug 12, 2002risk 0.00cvss —epss 0.01
Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter.
- CVE-2002-0531Aug 12, 2002risk 0.00cvss —epss 0.04
Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter.
- CVE-2002-0532Aug 12, 2002risk 0.00cvss —epss 0.00
EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters.
- CVE-2002-0533Aug 12, 2002risk 0.00cvss —epss 0.02
phpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags.
- CVE-2002-0534Aug 12, 2002risk 0.00cvss —epss 0.03
PostBoard 2.0.1 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags.
- CVE-2002-0616Aug 12, 2002risk 0.01cvss —epss 0.10
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
- CVE-2002-0617Aug 12, 2002risk 0.01cvss —epss 0.11
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook…
- CVE-2002-0618Aug 12, 2002risk 0.01cvss —epss 0.14
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
- CVE-2002-0619Aug 12, 2002risk 0.01cvss —epss 0.16
The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge…
- CVE-2002-0638Aug 12, 2002risk 0.00cvss —epss 0.01
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file…
- CVE-2002-0644Aug 12, 2002risk 0.04cvss —epss 0.11
Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
- CVE-2002-0645Aug 12, 2002risk 0.00cvss —epss 0.04
SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
- CVE-2002-0649Aug 12, 2002risk 0.10cvss —epss 0.85
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL…
- CVE-2002-0650Aug 12, 2002risk 0.01cvss —epss 0.18
The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two…
- CVE-2002-0655Aug 12, 2002risk 0.01cvss —epss 0.08
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
- CVE-2002-0656Aug 12, 2002risk 0.10cvss —epss 0.90
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
- CVE-2002-0657Aug 12, 2002risk 0.01cvss —epss 0.09
Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key.
- CVE-2002-0658Aug 12, 2002risk 0.03cvss —epss 0.01
OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
- CVE-2002-0659Aug 12, 2002risk 0.06cvss —epss 0.36
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
- CVE-2002-0660Aug 12, 2002risk 0.00cvss —epss 0.03
Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.
- CVE-2002-0661Aug 12, 2002risk 0.02cvss —epss 0.70
Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
- CVE-2002-0684Aug 12, 2002risk 0.00cvss —epss 0.06
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname…
- CVE-2002-0695Aug 12, 2002risk 0.01cvss —epss 0.17
Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
- CVE-2002-0697Aug 12, 2002risk 0.01cvss —epss 0.18
Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
- CVE-2002-0698Aug 12, 2002risk 0.02cvss —epss 0.20
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response.
- CVE-2002-0700Aug 12, 2002risk 0.01cvss —epss 0.08
Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function…
- CVE-2002-0710Aug 12, 2002risk 0.00cvss —epss 0.03
Directory traversal vulnerability in sendform.cgi 1.44 and earlier allows remote attackers to read arbitrary files by specifying the desired files in the BlurbFilePath parameter.
- CVE-2002-0718Aug 12, 2002risk 0.00cvss —epss 0.06
Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
- CVE-2002-0719Aug 12, 2002risk 0.01cvss —epss 0.10
SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
- CVE-2002-0728Aug 12, 2002risk 0.00cvss —epss 0.02
Buffer overflow in the progressive reader for libpng 1.2.x before 1.2.4, and 1.0.x before 1.0.14, allows attackers to cause a denial of service (crash) via a PNG data stream that has more IDAT data than indicated by the IHDR chunk.
- CVE-2002-0729Aug 12, 2002risk 0.01cvss —epss 0.11
Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
- CVE-2002-0730Aug 12, 2002risk 0.04cvss —epss 0.07
Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.
- CVE-2002-0731Aug 12, 2002risk 0.03cvss —epss 0.03
Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as respond.pl.
- CVE-2002-0732Aug 12, 2002risk 0.03cvss —epss 0.03
Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments.
- CVE-2002-0733Aug 12, 2002risk 0.04cvss —epss 0.08
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
- CVE-2002-0734Aug 12, 2002risk 0.04cvss —epss 0.07
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote attackers to execute arbitrary PHP code via a URL that sets the $b2inc variable to point to a malicious program stored on a remote server.
- CVE-2002-0735Aug 12, 2002risk 0.00cvss —epss 0.03
Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.
- CVE-2002-0736Aug 12, 2002risk 0.03cvss —epss 0.32
Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.
- CVE-2002-0737Aug 12, 2002risk 0.04cvss —epss 0.09
Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service (resource exhaustion) via DOS devices, using a URL that ends with a space and a null character.
- CVE-2002-0738Aug 12, 2002risk 0.00cvss —epss 0.03
MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting the SCRIPT tag into smaller pieces, (2) including the script in a SRC argument to an IMG tag, or (3)…
- CVE-2002-0739Aug 12, 2002risk 0.00cvss —epss 0.02
Cross-site scripting in PostCalendar 3.02 allows remote attackers to insert arbitrary HTML and script, and steal cookies, by modifying a calendar entry in its preview page.
- CVE-2002-0740Aug 12, 2002risk 0.03cvss —epss 0.01
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d (SPOOLDIR) argument.
- CVE-2002-0741Aug 12, 2002risk 0.04cvss —epss 0.08
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a long password argument and quickly killing the connection, which is not properly terminated by psyBNC.
- CVE-2002-0742Aug 12, 2002risk 0.00cvss —epss 0.01
Buffer overflow in pioout on AIX 4.3.3.
- CVE-2002-0743Aug 12, 2002risk 0.00cvss —epss 0.01
mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.
- CVE-2002-0744Aug 12, 2002risk 0.00cvss —epss 0.01
namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.
- CVE-2002-0745Aug 12, 2002risk 0.00cvss —epss 0.01
Buffer overflow in uucp in AIX 4.3.3.