CSV
180,406 results for "vulnerability" Page 31
CVE-2002-0148

Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.

Apr 22, 2002 2 affected product(s) NVD
7.5
CVSS
61.5%
EPSS
⚡ 48.4
CVE-2002-0311

Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.

May 31, 2002 2 affected product(s) NVD
10.0
CVSS
4.5%
EPSS
⚡ 41.4
CVE-2002-0193

Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.

May 29, 2002 4 affected product(s) NVD
7.5
CVSS
33.3%
EPSS
⚡ 40
CVE-2002-0075

Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.

Apr 22, 2002 2 affected product(s) NVD
7.5
CVSS
31.0%
EPSS
⚡ 39.3
CVE-2002-0190

Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.

May 29, 2002 7 affected product(s) NVD
7.5
CVSS
24.0%
EPSS
⚡ 37.2
CVE-2002-0153

Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability.

Apr 22, 2002 8 affected product(s) NVD
7.5
CVSS
17.7%
EPSS
⚡ 35.3
CVE-2002-0188

Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the second variant of the "Content Disposition" vulnerability.

May 29, 2002 4 affected product(s) NVD
7.5
CVSS
16.3%
EPSS
⚡ 34.9
CVE-2002-0189

Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.

May 29, 2002 5 affected product(s) NVD
7.5
CVSS
13.6%
EPSS
⚡ 34.1
CVE-2002-0242

Cross-site scripting vulnerability in Internet Explorer 6 earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed.

May 29, 2002 1 affected product(s) NVD
7.5
CVSS
11.4%
EPSS
⚡ 33.4
CVE-2002-0159

Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of administration function) or execute arbitrary code via format strings in the URL to port 2002.

Apr 22, 2002 6 affected product(s) NVD
7.5
CVSS
5.4%
EPSS
⚡ 31.6
CVE-2002-0257

Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.

May 29, 2002 6 affected product(s) NVD
7.5
CVSS
4.2%
EPSS
⚡ 31.3
CVE-2002-0374

Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name.

May 29, 2002 1 affected product(s) NVD
7.5
CVSS
3.8%
EPSS
⚡ 31.2
CVE-2002-0244

Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.

May 29, 2002 1 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2002-0168

Vulnerability in Imlib before 1.9.13 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by manipulating arguments that are passed to malloc, which results in a heap corruption.

Apr 22, 2002 13 affected product(s) NVD
7.5
CVSS
2.4%
EPSS
⚡ 30.7
CVE-2002-0307

Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl's eval function.

May 31, 2002 2 affected product(s) NVD
7.5
CVSS
2.3%
EPSS
⚡ 30.7
CVE-2002-0181

Cross-site scripting vulnerability in status.php3 for IMP 2.2.8 and HORDE 1.2.7 allows remote attackers to execute arbitrary web script and steal cookies of other IMP/HORDE users via the script parameter.

Apr 22, 2002 2 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.6
CVE-2002-0261

Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.

May 29, 2002 1 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2002-0166

Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly filtered by analog during display.

Apr 22, 2002 21 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2002-0205

Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter.

May 16, 2002 6 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2002-0238

Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.

May 29, 2002 3 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5