VYPR

CVEs

376,725 total · page 7431 of 7,535

  • CVE-2002-1071Oct 4, 2002
    risk 0.03cvss epss 0.03

    ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.

  • CVE-2002-1072Oct 4, 2002
    risk 0.03cvss epss 0.03

    ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.

  • CVE-2002-1073Oct 4, 2002
    risk 0.03cvss epss 0.06

    Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.

  • CVE-2002-1075Oct 4, 2002
    risk 0.03cvss epss 0.06

    Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.

  • CVE-2002-1076Oct 4, 2002
    risk 0.04cvss epss 0.14

    Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.

  • CVE-2002-1077Oct 4, 2002
    risk 0.04cvss epss 0.11

    IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.

  • CVE-2002-1078Oct 4, 2002
    risk 0.00cvss epss 0.03

    Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters.

  • CVE-2002-1079Oct 4, 2002
    risk 0.03cvss epss 0.05

    Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

  • CVE-2002-1080Oct 4, 2002
    risk 0.00cvss epss 0.02

    The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.

  • CVE-2002-1081Oct 4, 2002
    risk 0.00cvss epss 0.02

    The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.

  • CVE-2002-1082Oct 4, 2002
    risk 0.00cvss epss 0.01

    The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded.

  • CVE-2002-1083Oct 4, 2002
    risk 0.00cvss epss 0.02

    Directory traversal vulnerabilities in ezContents 1.41 and earlier allow remote attackers to cause ezContents to (1) create directories using the Maintain Images:Add New:Create Subdirectory item, or (2) list directories using the Maintain Images file listing, via .. (dot dot)…

  • CVE-2002-1084Oct 4, 2002
    risk 0.00cvss epss 0.03

    The VerifyLogin function in ezContents 1.41 and earlier does not properly halt program execution if a user fails to log in properly, which allows remote attackers to modify and view restricted information via HTTP POST requests.

  • CVE-2002-1085Oct 4, 2002
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.

  • CVE-2002-1086Oct 4, 2002
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.

  • CVE-2002-1087Oct 4, 2002
    risk 0.00cvss epss 0.02

    The scripts (1) createdir.php, (2) removedir.php and (3) uploadfile.php for ezContents 1.41 and earlier do not check credentials, which allows remote attackers to create or delete directories and upload files via a direct HTTP POST request.

  • CVE-2002-1088Oct 4, 2002
    risk 0.00cvss epss 0.03

    Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.

  • CVE-2002-1089Oct 4, 2002
    risk 0.03cvss epss 0.05

    rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.

  • CVE-2002-1090Oct 4, 2002
    risk 0.00cvss epss 0.02

    Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.

  • CVE-2002-1091Oct 4, 2002
    risk 0.00cvss epss 0.04

    Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.

  • CVE-2002-1092Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.

  • CVE-2002-1093Oct 4, 2002
    risk 0.00cvss epss 0.02

    HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption) via a long URL request.

  • CVE-2002-1094Oct 4, 2002
    risk 0.00cvss epss 0.02

    Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.

  • CVE-2002-1095Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.

  • CVE-2002-1096Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code.

  • CVE-2002-1097Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

  • CVE-2002-1098Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.

  • CVE-2002-1099Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.

  • CVE-2002-1100Oct 4, 2002
    risk 0.00cvss epss 0.02

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.

  • CVE-2002-1101Oct 4, 2002
    risk 0.03cvss epss 0.03

    Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

  • CVE-2002-1102Oct 4, 2002
    risk 0.00cvss epss 0.02

    The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes…

  • CVE-2002-1103Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.

  • CVE-2002-1104Oct 4, 2002
    risk 0.00cvss epss 0.02

    Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).

  • CVE-2002-1105Oct 4, 2002
    risk 0.00cvss epss 0.00

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password.

  • CVE-2002-1106Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks.

  • CVE-2002-1107Oct 4, 2002
    risk 0.00cvss epss 0.02

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing.

  • CVE-2002-1108Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.

  • CVE-2002-1109Oct 4, 2002
    risk 0.00cvss epss 0.00

    securetar, as used in AMaViS shell script 0.2.1 and earlier, allows users to cause a denial of service (CPU consumption) via a malformed TAR file, possibly via an incorrect file size parameter.

  • CVE-2002-1110Oct 4, 2002
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php.

  • CVE-2002-1111Oct 4, 2002
    risk 0.00cvss epss 0.01

    print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries for bugs that would otherwise be restricted.

  • CVE-2002-1112Oct 4, 2002
    risk 0.00cvss epss 0.02

    Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page.

  • CVE-2002-1113Oct 4, 2002
    risk 0.03cvss epss 0.03

    summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code.

  • CVE-2002-1114Oct 4, 2002
    risk 0.00cvss epss 0.03

    config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_include_page, (2) g_top_include_page, (3) g_css_include_file, (4) g_meta_include_file, or (5) a cookie.

  • CVE-2002-1115Oct 4, 2002
    risk 0.00cvss epss 0.02

    Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php.

  • CVE-2002-1116Oct 4, 2002
    risk 0.00cvss epss 0.01

    The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have access to any projects.

  • CVE-2002-1117Oct 4, 2002
    risk 0.00cvss epss 0.02

    Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.

  • CVE-2002-1119Oct 4, 2002
    risk 0.00cvss epss 0.00

    os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

  • CVE-2002-1127Oct 4, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.

  • CVE-2002-1128Oct 4, 2002
    risk 0.00cvss epss 0.00

    Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.

  • CVE-2002-1129Oct 4, 2002
    risk 0.03cvss epss 0.01

    Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.