|
353101
|
7.5 |
HIGH
|
ezne.net
|
ezboard_2000
|
Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, …
|
NVD-CWE-Other
|
CVE-2002-0263
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353102
|
7.5 |
HIGH
|
cooolsoft
|
powerftp
|
PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0264
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353103
|
4.6 |
MEDIUM
|
sawmill
|
sawmill
|
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file.
|
NVD-CWE-Other
|
CVE-2002-0265
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353104
|
5.0 |
MEDIUM
|
thunderstone_software
|
texis
|
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.
|
NVD-CWE-Other
|
CVE-2002-0266
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353105
|
10.0 |
HIGH
|
sips
|
sips
|
preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin c…
|
NVD-CWE-Other
|
CVE-2002-0267
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353106
|
7.2 |
HIGH
|
identix
|
biologon
|
Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.
|
NVD-CWE-Other
|
CVE-2002-0268
|
2016-10-18 11:17 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353107
|
7.5 |
HIGH
|
apache-ssl mod_ssl
|
apache-ssl mod_ssl
|
The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attac…
|
NVD-CWE-Other
|
CVE-2002-0082
|
2016-10-18 11:16 |
2002-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353108
|
5.0 |
MEDIUM
|
cvs
|
cvs
|
CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) via the diff capability.
|
NVD-CWE-Other
|
CVE-2002-0092
|
2016-10-18 11:16 |
2002-03-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353109
|
7.5 |
HIGH
|
boozt
|
boozt_standard
|
Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner.
|
NVD-CWE-Other
|
CVE-2002-0098
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353110
|
5.0 |
MEDIUM
|
michael_lamont
|
savant_webserver
|
Buffer overflow in Michael Lamont Savant Web Server 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP request to the cgi-bin directory in which the CGI program name con…
|
NVD-CWE-Other
|
CVE-2002-0099
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353111
|
7.5 |
HIGH
|
aol
|
aol_server
|
AOL AOLserver 3.4.2 Win32 allows remote attackers to bypass authentication and read password-protected files via a URL that directly references the file.
|
NVD-CWE-Other
|
CVE-2002-0100
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353112
|
4.6 |
MEDIUM
|
oracle
|
application_server_web_cache
|
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2)…
|
NVD-CWE-Other
|
CVE-2002-0103
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353113
|
5.0 |
MEDIUM
|
aftpd
|
aftpd
|
AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump.
|
NVD-CWE-Other
|
CVE-2002-0104
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353114
|
7.2 |
HIGH
|
caldera
|
unixware
|
CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable.
|
NVD-CWE-Other
|
CVE-2002-0105
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353115
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name.
|
NVD-CWE-Other
|
CVE-2002-0106
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353116
|
5.0 |
MEDIUM
|
cacheflow
|
cacheos
|
Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series of GET requests that do not end in with HTTP/1.0 or another v…
|
NVD-CWE-Other
|
CVE-2002-0107
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353117
|
6.4 |
MEDIUM
|
linksys
|
befn2ps4 befsr41 befsr81
|
Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the def…
|
NVD-CWE-Other
|
CVE-2002-0109
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353118
|
2.1 |
LOW
|
nevrona_designs
|
miramail
|
Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the…
|
NVD-CWE-Other
|
CVE-2002-0110
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353119
|
7.5 |
HIGH
|
funsoft
|
dinos_webserver
|
Directory traversal vulnerability in Funsoft Dino's Webserver 1.2 and earlier allows remote attackers to read files or execute arbitrary commands via a .. (dot dot) in the URL.
|
NVD-CWE-Other
|
CVE-2002-0111
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353120
|
5.0 |
MEDIUM
|
etype
|
eserv
|
Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.
|
NVD-CWE-Other
|
CVE-2002-0112
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353121
|
5.0 |
MEDIUM
|
palm
|
palm_os
|
Palm OS 3.5h and possibly other versions, as used in Handspring Visor and Xircom products, allows remote attackers to cause a denial of service via a TCP connect scan, e.g. from nmap.
|
NVD-CWE-Other
|
CVE-2002-0116
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353122
|
2.1 |
LOW
|
efax
|
efax
|
efax 0.9 and earlier, when installed setuid root, allows local users to read arbitrary files via the -d option, which prints the contents of the file in a warning message.
|
NVD-CWE-Other
|
CVE-2002-0129
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353123
|
7.2 |
HIGH
|
efax
|
efax
|
Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.
|
NVD-CWE-Other
|
CVE-2002-0130
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353124
|
5.0 |
MEDIUM
|
activestate
|
activepython
|
ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attacke…
|
NVD-CWE-Other
|
CVE-2002-0131
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353125
|
7.5 |
HIGH
|
avirt
|
avirt_gateway avirt_gateway_suite avirt_soho
|
Buffer overflows in Avirt Gateway Suite 4.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long header fields to the HTTP proxy, or (2) a long string …
|
NVD-CWE-Other
|
CVE-2002-0133
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353126
|
7.5 |
HIGH
|
avirt
|
avirt_gateway_suite
|
Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitra…
|
NVD-CWE-Other
|
CVE-2002-0134
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353127
|
7.2 |
HIGH
|
andreas_mueller
|
cdrdao
|
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configuration file.
|
NVD-CWE-Other
|
CVE-2002-0137
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353128
|
2.1 |
LOW
|
andreas_mueller
|
cdrdao
|
CDRDAO 1.1.4 and 1.1.5 allows local users to read arbitrary files via the show-data command.
|
NVD-CWE-Other
|
CVE-2002-0138
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353129
|
7.5 |
HIGH
|
pi3
|
pi3web
|
CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 characters long an…
|
NVD-CWE-Other
|
CVE-2002-0142
|
2016-10-18 11:16 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353130
|
7.5 |
HIGH
|
cisco
|
secure_access_control_server
|
Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash…
|
CWE-134
書式文字列の問題
|
CVE-2002-0159
|
2016-10-18 11:16 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353131
|
5.0 |
MEDIUM
|
cisco
|
secure_access_control_server
|
The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image fil…
|
NVD-CWE-Other
|
CVE-2002-0160
|
2016-10-18 11:16 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353132
|
6.2 |
MEDIUM
|
logwatch
|
logwatch
|
LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.
|
NVD-CWE-Other
|
CVE-2002-0162
|
2016-10-18 11:16 |
2002-03-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353133
|
7.5 |
HIGH
|
squid
|
squid
|
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a denial of service, and possibly execute arbitrary …
|
NVD-CWE-Other
|
CVE-2002-0163
|
2016-10-18 11:16 |
2002-03-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353134
|
7.2 |
HIGH
|
logwatch
|
logwatch
|
LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CVE-2002-0162.
|
NVD-CWE-Other
|
CVE-2002-0165
|
2016-10-18 11:16 |
2002-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353135
|
7.5 |
HIGH
|
zope
|
zope
|
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
|
NVD-CWE-Other
|
CVE-2002-0170
|
2016-10-18 11:16 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353136
|
7.5 |
HIGH
|
icecast
|
icecast
|
Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client.
|
NVD-CWE-Other
|
CVE-2002-0177
|
2016-10-18 11:16 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353137
|
7.2 |
HIGH
|
gnu
|
sharutils
|
uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or e…
|
NVD-CWE-Other
|
CVE-2002-0178
|
2016-10-18 11:16 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353138
|
7.5 |
HIGH
|
horde
|
horde imp
|
Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script param…
|
NVD-CWE-Other
|
CVE-2002-0181
|
2016-10-18 11:16 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353139
|
7.5 |
HIGH
|
psychoid
|
psybnc
|
psyBNC 2.3 beta and earlier allows remote attackers to spoof encrypted, trusted messages by sending lines that begin with the "[B]" sequence, which makes the message appear legitimate.
|
NVD-CWE-Other
|
CVE-2002-0197
|
2016-10-18 11:16 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353140
|
10.0 |
HIGH
|
paul_l_daniels
|
inflex ripmime
|
Buffer overflow in plDaniels ripMime 1.2.6 and earlier, as used in other programs such as xamime and inflex, allows remote attackers to execute arbitrary code via an attachment in a long filename.
|
NVD-CWE-Other
|
CVE-2002-0198
|
2016-10-18 11:16 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353141
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) …
|
NVD-CWE-Other
|
CVE-2001-1401
|
2016-10-18 11:15 |
2001-09-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353142
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection att…
|
NVD-CWE-Other
|
CVE-2001-1402
|
2016-10-18 11:15 |
2001-09-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353143
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and obser…
|
NVD-CWE-Other
|
CVE-2001-1403
|
2016-10-18 11:15 |
2001-09-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353144
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2001-1404
|
2016-10-18 11:15 |
2001-09-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353145
|
2.1 |
LOW
|
mozilla
|
bugzilla
|
Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.
|
NVD-CWE-Other
|
CVE-2001-1405
|
2016-10-18 11:15 |
2001-09-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353146
|
2.1 |
LOW
|
mozilla
|
bugzilla
|
process_bug.cgi in Bugzilla before 2.14 does not set the "groupset" bit when a bug is moved between product groups, which will cause the bug to have the old group's restrictions, which might not be a…
|
NVD-CWE-Other
|
CVE-2001-1406
|
2016-10-18 11:15 |
2001-09-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353147
|
7.5 |
HIGH
|
mozilla
|
bugzilla
|
Bugzilla before 2.14 allows Bugzilla users to bypass group security checks by marking a bug as the duplicate of a restricted bug, which adds the user to the CC list of the restricted bug and allows t…
|
NVD-CWE-Other
|
CVE-2001-1407
|
2016-10-18 11:15 |
2001-09-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353148
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.
|
NVD-CWE-Other
|
CVE-2001-1411
|
2016-10-18 11:15 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353149
|
2.1 |
LOW
|
apple
|
mac_os_x
|
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.
|
NVD-CWE-Other
|
CVE-2001-1412
|
2016-10-18 11:15 |
2003-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353150
|
7.2 |
HIGH
|
bsd
|
nvi
|
Format string vulnerability in nvi before 1.79 allows local users to gain privileges via format string specifiers in a filename.
|
NVD-CWE-Other
|
CVE-2001-1562
|
2016-10-18 11:15 |
2001-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|