Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-0313 | 1 Essen | 1 Essentia Web Server | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL. | |||||
CVE-2002-0314 | 3 Fasttrack, Grokster, Music City Networks | 3 Kazaa, Grokster, Morpheus | 2016-10-17 | 5.0 MEDIUM | N/A |
fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. | |||||
CVE-2002-0315 | 3 Fasttrack, Grokster, Music City Networks | 3 Kazaa, Grokster, Morpheus | 2016-10-17 | 7.5 HIGH | N/A |
fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header. | |||||
CVE-2002-0199 | 1 Nullsoft | 1 Shoutcast Server | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes. | |||||
CVE-2002-0200 | 1 Cyberstop | 1 Cyberstop Web Server | 2016-10-17 | 5.0 MEDIUM | N/A |
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name. | |||||
CVE-2002-0201 | 1 Cyberstop | 1 Cyberstop Web Server | 2016-10-17 | 5.0 MEDIUM | N/A |
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow. | |||||
CVE-2002-0203 | 1 Tarantella | 1 Tarantella Enterprise | 2016-10-17 | 5.0 MEDIUM | N/A |
ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter. | |||||
CVE-2002-0204 | 1 Gnu | 1 Chess | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to execute arbitrary code via a long command. | |||||
CVE-2002-0205 | 1 Plumtree | 1 Plumtree Corporate Portal | 2016-10-17 | 7.5 HIGH | N/A |
Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter. | |||||
CVE-2002-0211 | 1 Tarantella | 1 Tarantella Enterprise | 2016-10-17 | 6.2 MEDIUM | N/A |
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before it is executed. | |||||
CVE-2002-0212 | 1 Hosting Controller | 1 Hosting Controller | 2016-10-17 | 7.5 HIGH | N/A |
The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernames and makes it easier to conduct a brute force attack. | |||||
CVE-2002-0213 | 2 Sgi, Xinet | 2 Irix, K-ashare | 2016-10-17 | 2.1 LOW | N/A |
xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory. | |||||
CVE-2002-0226 | 1 Dcscripts | 1 Dcforum | 2016-10-17 | 7.5 HIGH | N/A |
retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user. | |||||
CVE-2002-0227 | 2 Kde, Kicq | 2 Kde, Kicq | 2016-10-17 | 5.0 MEDIUM | N/A |
KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message. | |||||
CVE-2002-0229 | 1 Php | 1 Php | 2016-10-17 | 7.5 HIGH | N/A |
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements. | |||||
CVE-2002-0230 | 1 Faq-o-matic | 1 Faq-o-matic | 2016-10-17 | 5.0 MEDIUM | N/A |
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message. | |||||
CVE-2002-0231 | 1 Khaled Mardam-bey | 1 Mirc | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname. | |||||
CVE-2002-0232 | 1 Mrtg | 1 Multi Router Traffic Grapher Cgi | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi. | |||||
CVE-2002-0233 | 1 Eshare Communications Inc. | 1 Eshare Expressions | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request. | |||||
CVE-2002-0234 | 1 Juniper | 1 Netscreen Screenos | 2016-10-17 | 2.1 LOW | N/A |
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections. |