VYPR

CVEs

342,793 total · page 6762 of 6,856

  • CVE-2002-0552Jul 3, 2002
    risk 0.04cvss epss 0.09

    Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file…

  • CVE-2002-0553Jul 3, 2002
    risk 0.03cvss epss 0.03

    Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.

  • CVE-2002-0554Jul 3, 2002
    risk 0.04cvss epss 0.07

    webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.

  • CVE-2002-0555Jul 3, 2002
    risk 0.00cvss epss 0.02

    IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.

  • CVE-2002-0556Jul 3, 2002
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

  • CVE-2002-0557Jul 3, 2002
    risk 0.00cvss epss 0.01

    Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to…

  • CVE-2002-0558Jul 3, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending in wildcard *.* characters.

  • CVE-2002-0559Jul 3, 2002
    risk 0.01cvss epss 0.13

    Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long…

  • CVE-2002-0560Jul 3, 2002
    risk 0.00cvss epss 0.04

    PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.

  • CVE-2002-0561Jul 3, 2002
    risk 0.01cvss epss 0.10

    The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings.

  • CVE-2002-0562Jul 3, 2002
    risk 0.01cvss epss 0.07

    The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa.

  • CVE-2002-0563Jul 3, 2002
    risk 0.04cvss epss 0.51

    The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and…

  • CVE-2002-0564Jul 3, 2002
    risk 0.00cvss epss 0.05

    PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.

  • CVE-2002-0565Jul 3, 2002
    risk 0.00cvss epss 0.06

    Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.

  • CVE-2002-0566Jul 3, 2002
    risk 0.00cvss epss 0.04

    PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.

  • CVE-2002-0567Jul 3, 2002
    risk 0.01cvss epss 0.09

    Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.

  • CVE-2002-0568Jul 3, 2002
    risk 0.06cvss epss 0.75

    Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.

  • CVE-2002-0569Jul 3, 2002
    risk 0.02cvss epss 0.19

    Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).

  • CVE-2002-0570Jul 3, 2002
    risk 0.00cvss epss 0.00

    The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.

  • CVE-2002-0571Jul 3, 2002
    risk 0.00cvss epss 0.03

    Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.

  • CVE-2002-0572Jul 3, 2002
    risk 0.03cvss epss 0.02

    FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid…

  • CVE-2002-0573Jul 3, 2002
    risk 0.01cvss epss 0.09

    Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.

  • CVE-2002-0574Jul 3, 2002
    risk 0.00cvss epss 0.02

    Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which prevents the entry from being…

  • CVE-2002-0615Jul 3, 2002
    risk 0.00cvss epss 0.06

    The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation".

  • CVE-2002-0620Jul 3, 2002
    risk 0.01cvss epss 0.12

    Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.

  • CVE-2002-0621Jul 3, 2002
    risk 0.01cvss epss 0.17

    Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.

  • CVE-2002-0622Jul 3, 2002
    risk 0.02cvss epss 0.19

    The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".

  • CVE-2002-0623Jul 3, 2002
    risk 0.02cvss epss 0.20

    Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".

  • CVE-2002-0631Jul 3, 2002
    risk 0.00cvss epss 0.00

    Unknown vulnerability in nveventd in NetVisualyzer on SGI IRIX 6.5 through 6.5.16 allows local users to write arbitrary files and gain root privileges.

  • CVE-2002-0639CriJul 3, 2002
    risk 0.65cvss 9.8epss 0.18

    Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.

  • CVE-2002-0640Jul 3, 2002
    risk 0.00cvss epss 0.27

    Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication…

  • CVE-2002-0651Jul 3, 2002
    risk 0.01cvss epss 0.13

    Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.

  • CVE-2002-0652Jul 3, 2002
    risk 0.04cvss epss 0.09

    xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().

  • CVE-2001-1300Jun 25, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.

  • CVE-2002-0006Jun 25, 2002
    risk 0.04cvss epss 0.08

    XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the client response when the…

  • CVE-2002-0146Jun 25, 2002
    risk 0.00cvss epss 0.01

    fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite memory via a message count that exceeds the boundaries of an array.

  • CVE-2002-0312Jun 25, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

  • CVE-2002-0313Jun 25, 2002
    risk 0.04cvss epss 0.10

    Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.

  • CVE-2002-0314Jun 25, 2002
    risk 0.00cvss epss 0.02

    fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.

  • CVE-2002-0315Jun 25, 2002
    risk 0.00cvss epss 0.02

    fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.

  • CVE-2002-0316Jun 25, 2002
    risk 0.04cvss epss 0.09

    Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag.

  • CVE-2002-0317Jun 25, 2002
    risk 0.00cvss epss 0.01

    Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter.

  • CVE-2002-0318Jun 25, 2002
    risk 0.00cvss epss 0.01

    FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.

  • CVE-2002-0319Jun 25, 2002
    risk 0.04cvss epss 0.07

    Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.

  • CVE-2002-0320Jun 25, 2002
    risk 0.01cvss epss 0.07

    Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field.

  • CVE-2002-0321Jun 25, 2002
    risk 0.00cvss epss 0.03

    Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.

  • CVE-2002-0322Jun 25, 2002
    risk 0.00cvss epss 0.02

    Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.

  • CVE-2002-0323Jun 25, 2002
    risk 0.00cvss epss 0.01

    comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.

  • CVE-2002-0324Jun 25, 2002
    risk 0.00cvss epss 0.03

    Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then…

  • CVE-2002-0325Jun 25, 2002
    risk 0.06cvss epss 0.38

    Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.