CSV
180,952 results for "vulnerability" Page 40
CVE-2002-0840 Exploit

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

Oct 11, 2002 47 affected product(s) NVD
6.8
CVSS
95.1%
EPSS
⚡ 65.7
CVE-2002-1217

Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses <frame> and <iframe> domain restrictions.

Oct 28, 2002 4 affected product(s) NVD
7.5
CVSS
49.8%
EPSS
⚡ 44.9
CVE-2002-1058

Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.

Oct 4, 2002 1 affected product(s) NVD
10.0
CVSS
4.4%
EPSS
⚡ 41.3
CVE-2002-0869

Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."

Nov 12, 2002 2 affected product(s) NVD
7.5
CVSS
21.6%
EPSS
⚡ 36.5
CVE-2002-1295

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."

Nov 29, 2002 1 affected product(s) NVD
7.5
CVSS
15.4%
EPSS
⚡ 34.6
CVE-2002-0029

Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.

Nov 29, 2002 18 affected product(s) NVD
7.5
CVSS
9.9%
EPSS
⚡ 33
CVE-2002-1157

Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.

Nov 4, 2002 1 affected product(s) NVD
7.5
CVSS
9.7%
EPSS
⚡ 32.9
CVE-2002-1275

Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."

Nov 12, 2002 7 affected product(s) NVD
7.5
CVSS
9.2%
EPSS
⚡ 32.8
CVE-2002-1180

A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."

Nov 12, 2002 1 affected product(s) NVD
7.5
CVSS
9.0%
EPSS
⚡ 32.7
CVE-2002-1281

Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote attackers to execute arbitrary code via a certain URL.

Nov 29, 2002 11 affected product(s) NVD
7.5
CVSS
5.2%
EPSS
⚡ 31.6
CVE-2002-1282

Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL.

Nov 29, 2002 11 affected product(s) NVD
7.5
CVSS
4.4%
EPSS
⚡ 31.3
CVE-2002-1242

SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.

Nov 12, 2002 1 affected product(s) NVD
7.5
CVSS
4.1%
EPSS
⚡ 31.2
CVE-2002-1244

Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.

Nov 12, 2002 4 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2002-1070

Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.

Oct 4, 2002 6 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-1202

Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files.

Oct 28, 2002 5 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2002-1307

Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.

Nov 29, 2002 3 affected product(s) NVD
6.8
CVSS
4.0%
EPSS
⚡ 28.4
CVE-2002-1167

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

Nov 4, 2002 2 affected product(s) NVD
6.8
CVSS
3.3%
EPSS
⚡ 28.2
CVE-2002-1053

Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error message.

Oct 4, 2002 1 affected product(s) NVD
6.8
CVSS
2.1%
EPSS
⚡ 27.8
CVE-2002-1168

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server response.

Nov 4, 2002 2 affected product(s) NVD
6.8
CVSS
1.6%
EPSS
⚡ 27.7
CVE-2002-1315

Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with another issue (CVE-2002-1316).

Nov 29, 2002 12 affected product(s) NVD
6.8
CVSS
1.6%
EPSS
⚡ 27.7