Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-1420 | 1 Openbsd | 1 Openbsd | 2016-10-17 | 7.2 HIGH | N/A |
Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check as a signed integer, but is later used as an unsigned integer during a data copying operation. | |||||
CVE-2002-1452 | 1 Mywebserver | 1 Mywebserver | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter. | |||||
CVE-2002-1453 | 1 Mywebserver | 1 Mywebserver | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message. | |||||
CVE-2002-1454 | 1 Mywebserver | 1 Mywebserver | 2016-10-17 | 5.0 MEDIUM | N/A |
MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message. | |||||
CVE-2002-1563 | 1 Stunnel | 1 Stunnel | 2016-10-17 | 1.2 LOW | N/A |
stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions that cause an inconsistency in the child counter. | |||||
CVE-2002-1568 | 1 Openssl | 1 Openssl | 2016-10-17 | 5.0 MEDIUM | N/A |
OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c. | |||||
CVE-2002-1647 | 1 Slashcode.com | 1 Slash | 2016-10-17 | 5.0 MEDIUM | N/A |
The quick login feature in Slash Slashcode does not redirect the user to an alternate URL when the wrong password is provided, which makes it easier for remote web sites to guess the proper passwords by reading the username and password from the Referrer URL. | |||||
CVE-2002-1664 | 1 Yahoo | 1 Messenger | 2016-10-17 | 6.4 MEDIUM | N/A |
Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information. | |||||
CVE-2002-1665 | 1 Yahoo | 1 Messenger | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long set_buddygrp field. | |||||
CVE-2002-1822 | 1 Ibm | 1 Http Server | 2016-10-17 | 5.0 MEDIUM | N/A |
IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP). | |||||
CVE-2002-1830 | 1 Openbb | 1 Openbb | 2016-10-17 | 5.0 MEDIUM | N/A |
Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters. | |||||
CVE-2002-1841 | 1 Noguska | 1 Nola | 2016-10-17 | 5.0 MEDIUM | N/A |
The document management module in NOLA 1.1.1 and 1.1.2 does not restrict the types of files that are uploaded, which allows remote attackers to upload and execute arbitrary PHP files with extensions such as .php4. | |||||
CVE-2002-1850 | 1 Apache | 1 Http Server | 2016-10-17 | 5.0 MEDIUM | N/A |
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script. | |||||
CVE-2002-1867 | 1 Bizdesign | 1 Imagefolio | 2016-10-17 | 7.5 HIGH | N/A |
The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption). | |||||
CVE-2002-2039 | 1 Qnx | 1 Rtos | 2016-10-17 | 2.1 LOW | N/A |
/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal. | |||||
CVE-2002-2048 | 1 Michael Baumer | 1 Pfinger | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in PFinger 0.7.8 client allows remote attackers to execute arbitrary code via a long query value passed to the (1) finger program, (2) -l, (3) -d, and (4) -t options. NOTE: if PFinger is not setuid or setgid, then this issue would not cross privilege boundaries and would not be considered a vulnerability. | |||||
CVE-2002-2054 | 1 Teekai | 1 Teekai Forum | 2016-10-17 | 7.5 HIGH | N/A |
TeeKai Forum 1.2 allows remote attackers to authenticate as the administrator and and gain privileged web forum access by setting the valid_level cookie to admin. | |||||
CVE-2002-2055 | 1 Teekai | 1 Teekai Tracking Online | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |||||
CVE-2002-2056 | 1 Teekai | 1 Teekai Forum | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in TeeKai Forum 1.2 allows remote attackers to inject arbitrary web script or HTML via the valid_username_online cookie. | |||||
CVE-2002-2057 | 1 Teekai | 1 Teekai Forum | 2016-10-17 | 5.0 MEDIUM | N/A |
TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'. |