CSV
180,952 results for "vulnerability" Page 42
CVE-2002-1584

Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.

Dec 27, 2002 59 affected product(s) NVD
10.0
CVSS
5.7%
EPSS
⚡ 41.7
CVE-2002-1699

SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.

Dec 31, 2002 2 affected product(s) NVD
10.0
CVSS
2.6%
EPSS
⚡ 40.8
CVE-2002-1573

Unspecified vulnerability in the pcilynx ieee1394 firewire driver (pcilynx.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors, related to "wrap handling."

Dec 31, 2002 47 affected product(s) NVD
10.0
CVSS
2.3%
EPSS
⚡ 40.7
CVE-2002-1689

Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

Dec 31, 2002 1 affected product(s) NVD
10.0
CVSS
2.1%
EPSS
⚡ 40.6
CVE-2002-1690

Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.

Dec 31, 2002 1 affected product(s) NVD
10.0
CVSS
1.4%
EPSS
⚡ 40.4
CVE-2002-1631

SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.

Dec 31, 2002 5 affected product(s) NVD
7.5
CVSS
7.7%
EPSS
⚡ 32.3
CVE-2002-1187

Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.

Dec 11, 2002 8 affected product(s) NVD
6.8
CVSS
15.0%
EPSS
⚡ 31.7
CVE-2002-1648

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2002-1342

Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.

Dec 18, 2002 4 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.6
CVE-2002-1381

Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.

Dec 23, 2002 3 affected product(s) NVD
7.2
CVSS
2.3%
EPSS
⚡ 29.5
CVE-2002-1296

Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.

Dec 23, 2002 7 affected product(s) NVD
7.2
CVSS
0.6%
EPSS
⚡ 29
CVE-2002-1334

Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.

Dec 11, 2002 5 affected product(s) NVD
6.8
CVSS
4.7%
EPSS
⚡ 28.6
CVE-2002-1703

Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users via the Term parameter.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2002-1708

Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
4.3%
EPSS
⚡ 28.5
CVE-2002-1316

importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).

Nov 29, 2002 12 affected product(s) NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8
CVE-2002-1341

Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.

Dec 18, 2002 5 affected product(s) NVD
6.8
CVSS
2.0%
EPSS
⚡ 27.8
CVE-2002-1681

Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragraph <P> tag.

Dec 31, 2002 5 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2002-1675

Format string vulnerability in the Cio_PrintF function of cio_main.c in Unreal IRCd 3.1.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers.

Dec 31, 2002 1 affected product(s) NVD
6.4
CVSS
2.7%
EPSS
⚡ 26.4
CVE-2002-1325

Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."

Dec 23, 2002 43 affected product(s) NVD
5.0
CVSS
13.9%
EPSS
⚡ 24.2
CVE-2002-1700

Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.

Dec 31, 2002 3 affected product(s) NVD
4.3
CVSS
22.9%
EPSS
⚡ 24.1