CSV
180,952 results for "vulnerability" Page 41
CVE-2002-1584

Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.

Dec 27, 2002 59 affected product(s) NVD
10.0
CVSS
5.7%
EPSS
⚡ 41.7
CVE-2002-1573

Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling."

Dec 31, 2002 47 affected product(s) NVD
10.0
CVSS
2.3%
EPSS
⚡ 40.7
CVE-2002-0869

Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."

Nov 12, 2002 2 affected product(s) NVD
7.5
CVSS
21.6%
EPSS
⚡ 36.5
CVE-2002-1295

The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."

Nov 29, 2002 1 affected product(s) NVD
7.5
CVSS
15.4%
EPSS
⚡ 34.6
CVE-2002-0029

Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.

Nov 29, 2002 18 affected product(s) NVD
7.5
CVSS
9.9%
EPSS
⚡ 33
CVE-2002-1157

Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.

Nov 4, 2002 1 affected product(s) NVD
7.5
CVSS
9.7%
EPSS
⚡ 32.9
CVE-2002-1275

Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."

Nov 12, 2002 7 affected product(s) NVD
7.5
CVSS
9.2%
EPSS
⚡ 32.8
CVE-2002-1180

A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."

Nov 12, 2002 1 affected product(s) NVD
7.5
CVSS
9.0%
EPSS
⚡ 32.7
CVE-2002-1631

SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.

Dec 31, 2002 5 affected product(s) NVD
7.5
CVSS
7.7%
EPSS
⚡ 32.3
CVE-2002-1187

Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.

Dec 11, 2002 8 affected product(s) NVD
6.8
CVSS
15.0%
EPSS
⚡ 31.7
CVE-2002-1281

Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote attackers to execute arbitrary code via a certain URL.

Nov 29, 2002 11 affected product(s) NVD
7.5
CVSS
5.2%
EPSS
⚡ 31.6
CVE-2002-1282

Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL.

Nov 29, 2002 11 affected product(s) NVD
7.5
CVSS
4.4%
EPSS
⚡ 31.3
CVE-2002-1242

SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.

Nov 12, 2002 1 affected product(s) NVD
7.5
CVSS
4.1%
EPSS
⚡ 31.2
CVE-2002-1244

Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.

Nov 12, 2002 4 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2002-1342

Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.

Dec 18, 2002 4 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.6
CVE-2002-1381

Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.

Dec 23, 2002 3 affected product(s) NVD
7.2
CVSS
2.3%
EPSS
⚡ 29.5
CVE-2002-1296

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

Dec 23, 2002 7 affected product(s) NVD
7.2
CVSS
0.6%
EPSS
⚡ 29
CVE-2002-1334

Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

Dec 11, 2002 5 affected product(s) NVD
6.8
CVSS
4.7%
EPSS
⚡ 28.6
CVE-2002-1307

Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.

Nov 29, 2002 3 affected product(s) NVD
6.8
CVSS
4.0%
EPSS
⚡ 28.4
CVE-2002-1167

Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.

Nov 4, 2002 2 affected product(s) NVD
6.8
CVSS
3.3%
EPSS
⚡ 28.2