CSV
180,467 results for "vulnerability" Page 36
CVE-2002-0661

Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.

Aug 12, 2002 12 affected product(s) NVD
7.5
CVSS
69.7%
EPSS
⚡ 50.9
CVE-2002-0796

Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.

Aug 12, 2002 7 affected product(s) NVD
10.0
CVSS
4.4%
EPSS
⚡ 41.3
CVE-2002-0746

Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.

Aug 12, 2002 1 affected product(s) NVD
10.0
CVSS
1.8%
EPSS
⚡ 40.6
CVE-2002-0619

The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
16.1%
EPSS
⚡ 34.8
CVE-2002-0719

SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
10.4%
EPSS
⚡ 33.1
CVE-2002-0504

Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
7.9%
EPSS
⚡ 32.4
CVE-2002-0733

Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
8.0%
EPSS
⚡ 32.4
CVE-2002-0730

Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
6.9%
EPSS
⚡ 32.1
CVE-2002-0855

Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.

Sep 5, 2002 1 affected product(s) NVD
7.5
CVSS
6.1%
EPSS
⚡ 31.8
CVE-2002-0645

SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
3.8%
EPSS
⚡ 31.2
CVE-2002-0660

Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.

Aug 12, 2002 2 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2002-0735

Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.

Aug 12, 2002 17 affected product(s) NVD
7.5
CVSS
2.9%
EPSS
⚡ 30.9
CVE-2002-0731

Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link that contains the script in arguments to demo scripts such as respond.pl.

Aug 12, 2002 4 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2002-0732

Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2002-0763

Vulnerability in administration server for HP VirtualVault 4.5 on HP-UX 11.04 allows remote web servers or privileged external processes to bypass access restrictions and establish connections to the server.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.6
CVE-2002-0520

Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag.

Aug 12, 2002 1 affected product(s) NVD
7.5
CVSS
1.6%
EPSS
⚡ 30.5
CVE-2002-0756

Cross-site scripting vulnerability in the authentication page for (1) Webmin 0.96 and (2) Usermin 0.90 allows remote attackers to insert script into an error page and possibly steal cookies.

Aug 12, 2002 10 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2002-0870

The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of the original attack, as identified by Cisco bug ID CSCdw08549.

Sep 5, 2002 2 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2002-0851

Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog.

Sep 5, 2002 1 affected product(s) NVD
7.2
CVSS
1.1%
EPSS
⚡ 29.1
CVE-2002-0526

Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls.

Aug 12, 2002 1 affected product(s) NVD
7.2
CVSS
0.5%
EPSS
⚡ 29