VYPR

CVEs

375,928 total · page 7429 of 7,519

  • CVE-2002-0261May 29, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.

  • CVE-2002-0262May 29, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in netget for Sybex E-Trainer web server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2002-0263May 29, 2002
    risk 0.04cvss epss 0.13

    Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, or (3) ezadmin.cgi.

  • CVE-2002-0264May 29, 2002
    risk 0.00cvss epss 0.02

    PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.

  • CVE-2002-0265May 29, 2002
    risk 0.03cvss epss 0.01

    Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file.

  • CVE-2002-0266May 29, 2002
    risk 0.04cvss epss 0.08

    Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.

  • CVE-2002-0267May 29, 2002
    risk 0.00cvss epss 0.03

    preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin command, which causes the Status line to be entered into the password file.

  • CVE-2002-0268May 29, 2002
    risk 0.00cvss epss 0.00

    Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.

  • CVE-2002-0269May 29, 2002
    risk 0.01cvss epss 0.11

    Internet Explorer 5.x and 6 interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain…

  • CVE-2002-0270May 29, 2002
    risk 0.00cvss epss 0.05

    Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect,…

  • CVE-2002-0271May 29, 2002
    risk 0.00cvss epss 0.00

    Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.

  • CVE-2002-0355May 29, 2002
    risk 0.00cvss epss 0.00

    netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.

  • CVE-2002-0356May 29, 2002
    risk 0.00cvss epss 0.00

    Vulnerability in XFS filesystem reorganizer (fsr_xfs) in SGI IRIX 6.5.10 and earlier allows local users to gain root privileges by overwriting critical system files.

  • CVE-2002-0362May 29, 2002
    risk 0.00cvss epss 0.04

    Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and a TLV type greater than 0x2711.

  • CVE-2002-0363May 29, 2002
    risk 0.00cvss epss 0.02

    ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice.

  • CVE-2002-0374May 29, 2002
    risk 0.00cvss epss 0.04

    Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name.

  • CVE-2002-0375May 29, 2002
    risk 0.04cvss epss 0.06

    Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter.

  • CVE-2002-0377May 29, 2002
    risk 0.00cvss epss 0.00

    Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.

  • CVE-2002-1447May 28, 2002
    risk 0.03cvss epss 0.01

    Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.

  • CVE-2002-1641May 27, 2002
    risk 0.01cvss epss 0.09

    Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors.

  • CVE-2001-1340May 21, 2002
    risk 0.00cvss epss 0.02

    Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service.

  • CVE-2001-1334May 19, 2002
    risk 0.03cvss epss 0.03

    Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.

  • CVE-2002-1280May 17, 2002
    risk 0.00cvss epss 0.01

    Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).

  • CVE-2002-0154May 16, 2002
    risk 0.02cvss epss 0.25

    Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.

  • CVE-2002-0157May 16, 2002
    risk 0.00cvss epss 0.00

    Nautilus 1.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the .nautilus-metafile.xml metadata file.

  • CVE-2002-0171May 16, 2002
    risk 0.00cvss epss 0.02

    IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges.

  • CVE-2002-0172May 16, 2002
    risk 0.00cvss epss 0.00

    /dev/ipfilter on SGI IRIX 6.5 is installed by /dev/MAKEDEV with insecure default permissions (644), which could allow a local user to cause a denial of service (traffic disruption).

  • CVE-2002-0173May 16, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in cpr for the eoe.sw.cpr SGI Checkpoint-Restart Software package on SGI IRIX 6.5.10 and earlier may allow local users to gain root privileges.

  • CVE-2002-0184HigMay 16, 2002
    risk 0.47cvss 7.8epss 0.01

    Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.

  • CVE-2002-0185May 16, 2002
    risk 0.00cvss epss 0.04

    mod_python version 2.7.6 and earlier allows a module indirectly imported by a published module to then be accessed via the publisher, which allows remote attackers to call possibly dangerous functions from the imported module.

  • CVE-2002-0196May 16, 2002
    risk 0.00cvss epss 0.02

    GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.

  • CVE-2002-0197May 16, 2002
    risk 0.00cvss epss 0.02

    psyBNC 2.3 beta and earlier allows remote attackers to spoof encrypted, trusted messages by sending lines that begin with the "[B]" sequence, which makes the message appear legitimate.

  • CVE-2002-0198May 16, 2002
    risk 0.00cvss epss 0.05

    Buffer overflow in plDaniels ripMime 1.2.6 and earlier, as used in other programs such as xamime and inflex, allows remote attackers to execute arbitrary code via an attachment in a long filename.

  • CVE-2002-0199May 16, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes.

  • CVE-2002-0200May 16, 2002
    risk 0.01cvss epss 0.07

    Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.

  • CVE-2002-0201May 16, 2002
    risk 0.05cvss epss 0.21

    Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.

  • CVE-2002-0202May 16, 2002
    risk 0.00cvss epss 0.00

    PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) modify the server configuration via the world-writeable /oekaki/ folder.

  • CVE-2002-0203May 16, 2002
    risk 0.00cvss epss 0.02

    ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.

  • CVE-2002-0204May 16, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to execute arbitrary code via a long command.

  • CVE-2002-0205May 16, 2002
    risk 0.00cvss epss 0.02

    Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter.

  • CVE-2002-0206May 16, 2002
    risk 0.04cvss epss 0.07

    index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.

  • CVE-2002-0207May 16, 2002
    risk 0.04cvss epss 0.07

    Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds the actual length of the header.

  • CVE-2002-0208May 16, 2002
    risk 0.00cvss epss 0.02

    PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a way that allows remote attackers to determine that the system is running PGPfire.

  • CVE-2002-0209May 16, 2002
    risk 0.03cvss epss 0.03

    Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with a half-closed session, which causes ACEdirector to send packets from the server…

  • CVE-2002-0210May 16, 2002
    risk 0.03cvss epss 0.01

    setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.

  • CVE-2002-0211May 16, 2002
    risk 0.03cvss epss 0.01

    Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed.

  • CVE-2002-0212May 16, 2002
    risk 0.00cvss epss 0.02

    The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernames and makes it easier to conduct a brute force attack.

  • CVE-2002-0213May 16, 2002
    risk 0.00cvss epss 0.00

    xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.

  • CVE-2002-0214May 16, 2002
    risk 0.00cvss epss 0.00

    Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the WEP key from the…

  • CVE-2002-0215May 16, 2002
    risk 0.04cvss epss 0.07

    Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.