Total
27865 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-1532 | 1 Surfcontrol | 1 Superscout Email Filter | 2008-09-05 | 5.0 MEDIUM | N/A |
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it. | |||||
CVE-2002-1521 | 1 Mdg Computer Services | 1 Web Server 4d | 2008-09-05 | 2.1 LOW | N/A |
Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges. | |||||
CVE-2002-1460 | 1 Leszek Krupinski | 1 L-forum | 2008-09-05 | 5.0 MEDIUM | N/A |
L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and attachment_type), which allows remote attackers to read arbitrary files. | |||||
CVE-2002-1504 | 1 Radiobird Software | 1 Webserver 4 Everyone | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in WebServer 4 Everyone 1.22 allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a URL. | |||||
CVE-2002-1481 | 1 Phpgb | 1 Phpgb | 2008-09-05 | 7.5 HIGH | N/A |
savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php. | |||||
CVE-2002-1451 | 1 Desiderata Software | 1 Blazix | 2008-09-05 | 5.0 MEDIUM | N/A |
Blazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that ends in a (1) "+" or (2) "\" (backslash) character. | |||||
CVE-2002-1520 | 2 Rapidstream, Watchguard | 2 Rapidstream, Firebox | 2008-09-05 | 10.0 HIGH | N/A |
The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows remote attackers to access CLI with administrator privileges. | |||||
CVE-2002-1437 | 1 Novell | 1 Netware | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to read arbitrary files via an HTTP request containing "..%5c" (URL-encoded dot-dot backslash) sequences. | |||||
CVE-2002-1510 | 1 Xfree86 Project | 1 X11r6 | 2008-09-05 | 10.0 HIGH | N/A |
xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist. | |||||
CVE-2002-1415 | 1 Webeasymail | 1 Webeasymail | 2008-09-05 | 5.0 MEDIUM | N/A |
Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests. | |||||
CVE-2002-1518 | 1 Sgi | 1 Irix | 2008-09-05 | 3.6 LOW | N/A |
mv in IRIX 6.5 creates a directory with world-writable permissions while moving a directory, which could allow local users to modify files and directories. | |||||
CVE-2002-1512 | 1 Tolis Group | 1 Bru | 2008-09-05 | 6.2 MEDIUM | N/A |
xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the xbru_dscheck.dd temporary file. | |||||
CVE-2002-1413 | 1 Novell | 1 Netware | 2008-09-05 | 7.5 HIGH | N/A |
RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection. | |||||
CVE-2002-1514 | 1 Borland Software | 1 Interbase | 2008-09-05 | 7.2 HIGH | N/A |
gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file. | |||||
CVE-2002-1515 | 1 Coolforum | 1 Coolforum | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter. | |||||
CVE-2002-1505 | 1 Woltlab | 1 Burning Board | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter. | |||||
CVE-2002-1446 | 1 Ncipher | 1 Pkcs 11 Library | 2008-09-05 | 5.0 MEDIUM | N/A |
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages. | |||||
CVE-2002-1534 | 1 Macromedia | 1 Flash Player | 2008-09-05 | 5.0 MEDIUM | N/A |
Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share. | |||||
CVE-2002-1533 | 1 Jetty | 1 Jetty | 2008-09-05 | 5.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a). | |||||
CVE-2002-1466 | 1 Cafelog | 1 B2 | 2008-09-05 | 10.0 HIGH | N/A |
CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable. |