CSV
180,949 results for "vulnerability" Page 43
CVE-2002-1794

Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.

Dec 31, 2002 4 affected product(s) NVD
10.0
CVSS
4.1%
EPSS
⚡ 41.2
CVE-2002-1699

SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.

Dec 31, 2002 2 affected product(s) NVD
10.0
CVSS
2.6%
EPSS
⚡ 40.8
CVE-2002-1689

Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.

Dec 31, 2002 1 affected product(s) NVD
10.0
CVSS
2.1%
EPSS
⚡ 40.6
CVE-2002-1690

Unknown vulnerability in AIX before 4.0 with unknown attack vectors and unknown impact, aka "security issue," as fixed by APAR IY28225.

Dec 31, 2002 1 affected product(s) NVD
10.0
CVSS
1.4%
EPSS
⚡ 40.4
CVE-2002-1744

Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
65.2%
EPSS
⚡ 39.6
CVE-2002-1648

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters.

Dec 31, 2002 1 affected product(s) NVD
7.5
CVSS
3.4%
EPSS
⚡ 31
CVE-2002-1720

SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field.

Dec 31, 2002 6 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2002-1788

Format string vulnerability in the nn_exitmsg function in nn 6.6.0 through 6.6.3 allows remote NNTP servers to execute arbitrary code via format strings in server responses.

Dec 31, 2002 4 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2002-1790

The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.

Dec 31, 2002 5 affected product(s) NVD
5.0
CVSS
34.0%
EPSS
⚡ 30.2
CVE-2002-1741

Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.

Dec 31, 2002 7 affected product(s) NVD
7.2
CVSS
1.1%
EPSS
⚡ 29.1
CVE-2002-1748

Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts.

Dec 31, 2002 5 affected product(s) NVD
7.2
CVSS
0.8%
EPSS
⚡ 29
CVE-2002-1789

Format string vulnerability in newsx NNTP client before 1.4.8 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a call to the syslog function.

Dec 31, 2002 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2002-1703

Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as other users via the Term parameter.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
4.2%
EPSS
⚡ 28.5
CVE-2002-1708

Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
4.3%
EPSS
⚡ 28.5
CVE-2002-1727

Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.

Dec 31, 2002 2 affected product(s) NVD
6.8
CVSS
4.3%
EPSS
⚡ 28.5
CVE-2002-1681

Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragraph <P> tag.

Dec 31, 2002 5 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2002-1724

Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2002-1729

Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2002-1675

Format string vulnerability in the Cio_PrintF function of cio_main.c in Unreal IRCd 3.1.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers.

Dec 31, 2002 1 affected product(s) NVD
6.4
CVSS
2.7%
EPSS
⚡ 26.4
CVE-2002-1709

SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.

Dec 31, 2002 1 affected product(s) NVD
6.4
CVSS
1.2%
EPSS
⚡ 25.9