|
357501
|
5.0 |
MEDIUM
|
macromedia
|
jrun
|
Unknown "file disclosure" vulnerability in Macromedia JRun 3.0, 3.1, and 4.0, related to a log file or jrun.ini, with unknown impact.
|
NVD-CWE-Other
|
CVE-2002-2187
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357502
|
4.9 |
MEDIUM
|
openbsd
|
openbsd
|
OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error.
|
NVD-CWE-Other
|
CVE-2002-2188
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357503
|
5.1 |
MEDIUM
|
activxperts_software microsoft
|
activwebserver windows_2003_server
|
Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.
|
NVD-CWE-Other
|
CVE-2002-2189
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357504
|
7.5 |
HIGH
|
artscore_studios
|
cutecast_forum
|
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
|
NVD-CWE-Other
|
CVE-2002-2190
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357505
|
5.0 |
MEDIUM
|
lotus
|
domino
|
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non…
|
NVD-CWE-Other
|
CVE-2002-2191
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357506
|
5.0 |
MEDIUM
|
lotus
|
domino
|
This issue is present on Lotus Domino Server with the 'DominoNoBanner' set to a value of '1'.
|
NVD-CWE-Other
|
CVE-2002-2191
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357507
|
4.3 |
MEDIUM
|
perception
|
liteserve
|
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query…
|
NVD-CWE-Other
|
CVE-2002-2192
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357508
|
4.3 |
MEDIUM
|
perception
|
liteserve
|
This vulnerability is limited to server configurations with Wildcard DNS enabled.
|
NVD-CWE-Other
|
CVE-2002-2192
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357509
|
4.3 |
MEDIUM
|
mojo_mail
|
mojo_mail
|
Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter.
|
NVD-CWE-Other
|
CVE-2002-2193
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357510
|
5.0 |
MEDIUM
|
nullsoft
|
winamp
|
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.
|
NVD-CWE-Other
|
CVE-2002-2195
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357511
|
7.5 |
HIGH
|
samba
|
samba
|
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to execute arbitrary code via a buffer overflow attack.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2196
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357512
|
10.0 |
HIGH
|
zmailer
|
zmailer
|
Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing from an IPv6 address, possibly using an address that resolves to a long hostname.
|
NVD-CWE-Other
|
CVE-2002-2198
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357513
|
10.0 |
HIGH
|
webmin
|
webmin
|
The Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the printer name.
|
NVD-CWE-Other
|
CVE-2002-2201
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357514
|
3.8 |
LOW
|
microsoft
|
outlook_express
|
Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.
|
NVD-CWE-Other
|
CVE-2002-2202
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357515
|
3.8 |
LOW
|
microsoft
|
outlook_express
|
This vulnerability affects Outlook Express 6.0 on any version of the Windows OS.
|
NVD-CWE-Other
|
CVE-2002-2202
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357516
|
7.5 |
HIGH
|
redhat
|
redhat_package_manager
|
The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicio…
|
NVD-CWE-Other
|
CVE-2002-2204
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357517
|
7.5 |
HIGH
|
redhat
|
redhat_package_manager
|
A large degree of social engineering and user interaction is neccessary to exploit this vulnerbility.
|
NVD-CWE-Other
|
CVE-2002-2204
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357518
|
5.0 |
MEDIUM
|
webresolve
|
webresolve
|
Buffer overflow in Webresolve 0.1.0 and earlier allows remote attackers to execute arbitrary code by connecting to the server from an IP address that resolves to a long hostname.
|
NVD-CWE-Other
|
CVE-2002-2205
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357519
|
7.8 |
HIGH
|
symantec
|
norton_antivirus
|
The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries.
|
NVD-CWE-Other
|
CVE-2002-2206
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357520
|
10.0 |
HIGH
|
eric_rescorla
|
ssldump
|
Buffer overflow in ssldump 0.9b2 and earlier, when running in decryption mode, allows remote attackers to execute arbitrary code via a long RSA PreMasterSecret.
|
NVD-CWE-Other
|
CVE-2002-2207
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357521
|
10.0 |
HIGH
|
pablo_software_solutions
|
baby_ftp_server
|
Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2002-2209
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357522
|
6.2 |
MEDIUM
|
openoffice
|
openoffice
|
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink attack on the USERNAME_autoresponse.conf temporary file.
|
NVD-CWE-Other
|
CVE-2002-2210
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357523
|
5.0 |
MEDIUM
|
isc fujitsu
|
bind uxp_v
|
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that …
|
NVD-CWE-Other
|
CVE-2002-2212
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357524
|
5.0 |
MEDIUM
|
infoblox isc
|
dns_one bind
|
The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack th…
|
NVD-CWE-Other
|
CVE-2002-2213
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357525
|
5.0 |
MEDIUM
|
php
|
php
|
The php_if_imap_mime_header_decode function in the IMAP functionality in PHP before 4.2.2 allows remote attackers to cause a denial of service (crash) via an e-mail header with a long "To" header.
|
NVD-CWE-Other
|
CVE-2002-2214
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357526
|
5.0 |
MEDIUM
|
php
|
php
|
The imap_header function in the IMAP functionality for PHP before 4.3.0 allows remote attackers to cause a denial of service via an e-mail message with a large number of "To" addresses, which trigger…
|
NVD-CWE-Other
|
CVE-2002-2215
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357527
|
5.0 |
MEDIUM
|
php
|
php
|
This vulnerability is addressed in the following product release:
PHP, PHP, 4.3.0
|
NVD-CWE-Other
|
CVE-2002-2215
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357528
|
5.0 |
MEDIUM
|
soft3304
|
04webserver
|
Soft3304 04WebServer before 1.20 does not properly process URL strings, which allows remote attackers to obtain unspecified sensitive information.
|
NVD-CWE-Other
|
CVE-2002-2216
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357529
|
10.0 |
HIGH
|
sips
|
sips
|
CRLF injection vulnerability in the setUserValue function in sipssys/code/site.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) before 20020209 has unknown impact, possibly gainin…
|
NVD-CWE-Other
|
CVE-2002-2218
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357530
|
6.2 |
MEDIUM
|
chetcpasswd
|
chetcpasswd
|
Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2002-2220
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357531
|
6.2 |
MEDIUM
|
chetcpasswd
|
chetcpasswd
|
Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issu…
|
NVD-CWE-Other
|
CVE-2002-2221
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357532
|
5.1 |
MEDIUM
|
safenet
|
softremote_vpn_client
|
SafeNet VPN client allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly involving buffer overflo…
|
NVD-CWE-Other
|
CVE-2002-2225
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357533
|
6.4 |
MEDIUM
|
mailscanner
|
mailscanner
|
MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate c…
|
CWE-20
Improper Input Validation
|
CVE-2002-2228
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357534
|
5.0 |
MEDIUM
|
sapio_design_ltd
|
webreflex
|
Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request.
|
CWE-22
Path Traversal
|
CVE-2002-2229
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357535
|
8.5 |
HIGH
|
mollensoft_software
|
enceladus_server_suite
|
Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2002-2232
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357536
|
4.3 |
MEDIUM
|
netscreen
|
screenos
|
NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests.
|
CWE-16
Configuration
|
CVE-2002-2234
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357537
|
5.0 |
MEDIUM
|
jelsoft
|
vbulletin
|
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which fac…
|
CWE-189
Numeric Errors
|
CVE-2002-2235
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357538
|
10.0 |
HIGH
|
apt-www-proxy
|
apt-www-proxy
|
Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2002-2236
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357539
|
5.0 |
MEDIUM
|
netbsd
|
ftpd
|
ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls an…
|
CWE-189
Numeric Errors
|
CVE-2002-2245
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357540
|
10.0 |
HIGH
|
hp
|
secure_web_server_for_tru64
|
Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might…
|
NVD-CWE-noinfo
|
CVE-2002-2264
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357541
|
10.0 |
HIGH
|
hp
|
secure_web_server_for_tru64
|
More Information: http://www.securityfocus.com/bid/6175/info
|
NVD-CWE-noinfo
|
CVE-2002-2264
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357542
|
5.0 |
MEDIUM
|
pyramid
|
benhur_software_update
|
The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20.
|
NVD-CWE-Other
|
CVE-2002-2307
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357543
|
5.0 |
MEDIUM
|
netscape
|
communicator
|
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL ta…
|
NVD-CWE-Other
|
CVE-2002-2308
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357544
|
7.8 |
HIGH
|
php
|
php
|
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to cause a denial of service via a direct request without arguments.
|
CWE-399
Resource Management Errors
|
CVE-2002-2309
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357545
|
5.0 |
MEDIUM
|
kryptronic
|
clickcartpro
|
ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and pa…
|
CWE-255
Credentials Management
|
CVE-2002-2310
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357546
|
5.8 |
MEDIUM
|
opera_software
|
opera
|
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a web…
|
NVD-CWE-Other
|
CVE-2002-2312
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357547
|
8.8 |
HIGH
|
qualcomm
|
eudora
|
Eudora email client 5.1.1, with "use Microsoft viewer" enabled, allows remote attackers to execute arbitrary programs via an HTML email message containing a META refresh tag that references an embedd…
|
NVD-CWE-Other
|
CVE-2002-2313
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357548
|
5.0 |
MEDIUM
|
mozilla
|
mozilla
|
Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which causes the host/path check to fail.
|
CWE-20
Improper Input Validation
|
CVE-2002-2314
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357549
|
7.8 |
HIGH
|
cisco
|
ios
|
Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the rou…
|
NVD-CWE-Other
|
CVE-2002-2315
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357550
|
5.0 |
MEDIUM
|
cisco
|
catos
|
Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switc…
|
NVD-CWE-Other
|
CVE-2002-2316
|
2008-09-6 05:32 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|