CSV
180,949 results for "vulnerability" Page 44
CVE-2002-1794

Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.

Dec 31, 2002 4 affected product(s) NVD
10.0
CVSS
4.1%
EPSS
⚡ 41.2
CVE-2002-1847

Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability.

Dec 31, 2002 5 affected product(s) NVD
7.5
CVSS
33.6%
EPSS
⚡ 40.1
CVE-2002-1744

Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).

Dec 31, 2002 1 affected product(s) NVD
5.0
CVSS
65.2%
EPSS
⚡ 39.6
CVE-2002-1720

SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the password field.

Dec 31, 2002 6 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2002-1788

Format string vulnerability in the nn_exitmsg function in nn 6.6.0 through 6.6.3 allows remote NNTP servers to execute arbitrary code via format strings in server responses.

Dec 31, 2002 4 affected product(s) NVD
7.5
CVSS
2.1%
EPSS
⚡ 30.6
CVE-2002-1817

Unknown vulnerability in Veritas Cluster Server (VCS) 1.2 for WindowsNT, Cluster Server 1.3.0 for Solaris, and Cluster Server 1.3.1 for HP-UX allows attackers to gain privileges via unknown attack vectors.

Dec 31, 2002 4 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2002-1790

The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.

Dec 31, 2002 5 affected product(s) NVD
5.0
CVSS
34.0%
EPSS
⚡ 30.2
CVE-2002-1741

Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to delete arbitrary files via a ".." (dot dot) in the Attachments parameter.

Dec 31, 2002 7 affected product(s) NVD
7.2
CVSS
1.1%
EPSS
⚡ 29.1
CVE-2002-1748

Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts.

Dec 31, 2002 5 affected product(s) NVD
7.2
CVSS
0.8%
EPSS
⚡ 29
CVE-2002-1789

Format string vulnerability in newsx NNTP client before 1.4.8 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a call to the syslog function.

Dec 31, 2002 1 affected product(s) NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2002-1727

Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL.

Dec 31, 2002 2 affected product(s) NVD
6.8
CVSS
4.3%
EPSS
⚡ 28.5
CVE-2002-1724

Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2002-1729

Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message.

Dec 31, 2002 1 affected product(s) NVD
6.8
CVSS
1.3%
EPSS
⚡ 27.6
CVE-2002-1825

Format string vulnerability in PerlRTE_example1.pl in WASD 7.1, 7.2.0 through 7.2.3, and 8.0.0 allows remote attackers to execute arbitrary commands or crash the server via format strings in the $name variable.

Dec 31, 2002 6 affected product(s) NVD
6.4
CVSS
2.2%
EPSS
⚡ 26.3
CVE-2002-1819

Directory traversal vulnerability in TinyHTTPD 0.1 .0 allows remote attackers to read or execute arbitrary files via a ".." (dot dot) in the URL.

Dec 31, 2002 1 affected product(s) NVD
6.4
CVSS
1.8%
EPSS
⚡ 26.1
CVE-2002-1709

SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.

Dec 31, 2002 1 affected product(s) NVD
6.4
CVSS
1.2%
EPSS
⚡ 25.9
CVE-2002-1783

CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or (2) file functions.

Dec 31, 2002 17 affected product(s) NVD
5.0
CVSS
16.7%
EPSS
⚡ 25
CVE-2002-1795

Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

Dec 31, 2002 1 affected product(s) NVD
4.3
CVSS
16.8%
EPSS
⚡ 22.2
CVE-2002-1784

Unknown vulnerability in inetd in HP Tru64 Unix 4.0f through 5.1a allows remote attackers to cause a denial of service via unknown attack vectors.

Dec 31, 2002 5 affected product(s) NVD
5.0
CVSS
3.1%
EPSS
⚡ 20.9
CVE-2002-1824

Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-the-middle attack. NOTE: it is not clear whether this poses a vulnerability.

Dec 31, 2002 2 affected product(s) NVD
5.0
CVSS
2.6%
EPSS
⚡ 20.8