CVE-2002-0 to CVE-2002-999
272 CVEs with public proof-of-concept exploits.
- CVE-2002-00021 PoCFormat string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious…
- CVE-2002-00042 PoCsHeap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which…
- CVE-2002-00051 PoCBuffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code…
- CVE-2002-00061 PoCXChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as…
- CVE-2002-00101 PoCBugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter…
- CVE-2002-00131 PoCVulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of…
- CVE-2002-00221 PoCBuffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to…
- CVE-2002-00231 PoCInternet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function,…
- CVE-2002-00312 PoCsBuffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long…
- CVE-2002-00331 PoCHeap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request…
- CVE-2002-00432 PoCssudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain…
- CVE-2002-00483 PoCsMultiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote…
- CVE-2002-00611 PoCApache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell…
- CVE-2002-00681 PoCSquid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an…
- CVE-2002-00794 PoCsBuffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows…
- CVE-2002-00811 PoCBuffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote…
- CVE-2002-00826 PoCsThe dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory…
- CVE-2002-00832 PoCsOff-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
- CVE-2002-00951 PoCThe default configuration of BSCW (Basic Support for Cooperative Work) 3.x and possibly version 4 enables user self registration, which…
- CVE-2002-00982 PoCsBuffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long…
- CVE-2002-01061 PoCBEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain…
- CVE-2002-01071 PoCWeb administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive information via a series…
- CVE-2002-01121 PoCEtype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.
- CVE-2002-01151 PoCSnort 1.8.3 does not properly define the minimum ICMP header size, which allows remote attackers to cause a denial of service (crash and…
- CVE-2002-01171 PoCCross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute…
- CVE-2002-01181 PoCCross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attackers to execute…
- CVE-2002-01282 PoCscgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code,…
- CVE-2002-01301 PoCBuffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.
- CVE-2002-01321 PoCBuffer overflow in Chinput 3.0 allows local users to execute arbitrary code via a long HOME environment variable.
- CVE-2002-01331 PoCBuffer overflows in Avirt Gateway Suite 4.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via…
- CVE-2002-01351 PoCNetopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of…
- CVE-2002-01374 PoCsCDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configuration file.
- CVE-2002-01401 PoCDomain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute…
- CVE-2002-01421 PoCCGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of…
- CVE-2002-01431 PoCBuffer overflow in Eterm of Enlightenment Imlib2 1.0.4 and earlier allows local users to execute arbitrary code via a long HOME…
- CVE-2002-01481 PoCCross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary…
- CVE-2002-01531 PoCInternet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML…
- CVE-2002-01581 PoCBuffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line…
- CVE-2002-01621 PoCLogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.
- CVE-2002-01631 PoCHeap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers…
- CVE-2002-01772 PoCsBuffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3…
- CVE-2002-01841 PoCSudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root…
- CVE-2002-01861 PoCBuffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data…
- CVE-2002-01871 PoCCross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via…
- CVE-2002-01891 PoCCross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a…
- CVE-2002-01911 PoCMicrosoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script…
- CVE-2002-01931 PoCMicrosoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and…
- CVE-2002-02001 PoCCyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.
- CVE-2002-02012 PoCsCyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via…
- CVE-2002-02061 PoCindex.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute…
- CVE-2002-02071 PoCBuffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value…
- CVE-2002-02091 PoCNortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote…
- CVE-2002-02101 PoCsetlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on…
- CVE-2002-02112 PoCsRace condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip"…
- CVE-2002-02151 PoCAgora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting…
- CVE-2002-02271 PoCKICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.
- CVE-2002-02293 PoCsSafe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access…
- CVE-2002-02301 PoCCross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other…
- CVE-2002-02311 PoCBuffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.
- CVE-2002-02361 PoCLucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass…
- CVE-2002-02393 PoCsBuffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or…
- CVE-2002-02441 PoCDirectory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the…
- CVE-2002-02462 PoCsFormat string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying…
- CVE-2002-02501 PoCWeb configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized…
- CVE-2002-02522 PoCsBuffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a…
- CVE-2002-02561 PoCThe telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long…
- CVE-2002-02631 PoCBuffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a…
- CVE-2002-02651 PoCSawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain…
- CVE-2002-02661 PoCThunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which…
- CVE-2002-02761 PoCBuffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2000, allows remote…
- CVE-2002-02801 PoCBuffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long…
- CVE-2002-02861 PoCThe GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a…
- CVE-2002-02883 PoCsDirectory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in…
- CVE-2002-02893 PoCsBuffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP…
- CVE-2002-02962 PoCsThe installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning"…
- CVE-2002-03001 PoCgnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by…
- CVE-2002-03112 PoCsVulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell…
- CVE-2002-03131 PoCBuffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via…
- CVE-2002-03161 PoCCross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB…
- CVE-2002-03191 PoCCross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies…
- CVE-2002-03251 PoCDirectory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in…
- CVE-2002-03272 PoCsBuffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.
- CVE-2002-03281 PoCCross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and…
- CVE-2002-03291 PoCCross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other…
- CVE-2002-03302 PoCsCross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary…
- CVE-2002-03311 PoCDirectory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot…
- CVE-2002-03322 PoCsBuffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a…
- CVE-2002-03332 PoCsDirectory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with…
- CVE-2002-03341 PoCxtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows local users to modify files via a symlink attack on the .xtell-log file.
- CVE-2002-03351 PoCBuffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly…
- CVE-2002-03361 PoCBuffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly…
- CVE-2002-03381 PoCThe Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment…
- CVE-2002-03461 PoCCross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via…
- CVE-2002-03471 PoCDirectory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the…
- CVE-2002-03481 PoCservice.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service…
- CVE-2002-03674 PoCsKEVsmss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which…
- CVE-2002-03711 PoCBuffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote…
- CVE-2002-03751 PoCCross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the…
- CVE-2002-03792 PoCsBuffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy…
- CVE-2002-03861 PoCThe administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of…
- CVE-2002-03881 PoCCross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or…
- CVE-2002-03925 PoCsApache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute…
- CVE-2002-04061 PoCMenasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections…
- CVE-2002-04131 PoCCross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose…
- CVE-2002-04191 PoCInformation leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute…
- CVE-2002-04221 PoCIIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured…
- CVE-2002-04302 PoCsMultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite…
- CVE-2002-04311 PoCXTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.
- CVE-2002-04361 PoCsscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters…
- CVE-2002-04401 PoCTrend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web…
- CVE-2002-04482 PoCsXerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains…
- CVE-2002-04511 PoCfilemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in…
- CVE-2002-04541 PoCQpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very…
- CVE-2002-04611 PoCInternet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page…
- CVE-2002-04683 PoCsBuffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long…
- CVE-2002-04831 PoCindex.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file…
- CVE-2002-04841 PoCmove_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attackers to upload…
- CVE-2002-04861 PoCIntellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the…
- CVE-2002-04921 PoCdcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.
- CVE-2002-04951 PoCcsSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup…
- CVE-2002-04991 PoCThe d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error,…
- CVE-2002-05021 PoCCitrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.
- CVE-2002-05041 PoCCross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows…
- CVE-2002-05161 PoCSquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the THEME variable in a…
- CVE-2002-05172 PoCsBuffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local…
- CVE-2002-05251 PoCFormat string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to…
- CVE-2002-05352 PoCsCross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an…
- CVE-2002-05361 PoCPHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the…
- CVE-2002-05391 PoCDemarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored…
- CVE-2002-05401 PoCNortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and…
- CVE-2002-05421 PoCmail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow…
- CVE-2002-05432 PoCsDirectory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the…
- CVE-2002-05441 PoCAprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which…
- CVE-2002-05522 PoCsMultiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly…
- CVE-2002-05531 PoCCross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by…
- CVE-2002-05541 PoCwebdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL…
- CVE-2002-05721 PoCFreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by…
- CVE-2002-05732 PoCsFormat string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code…
- CVE-2002-05751 PoCBuffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing…
- CVE-2002-05881 PoCPVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying…
- CVE-2002-05891 PoCPVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with…
- CVE-2002-05901 PoCCross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as…
- CVE-2002-05911 PoCDirectory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files…
- CVE-2002-05951 PoCBuffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via…
- CVE-2002-05972 PoCsLANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of…
- CVE-2002-05991 PoCBlahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs…
- CVE-2002-06062 PoCsBuffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2002-06071 PoCmembers.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack…
- CVE-2002-06081 PoCBuffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner.
- CVE-2002-06111 PoCDirectory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified dot dot) in the…
- CVE-2002-06121 PoCFileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot parameters.
- CVE-2002-06131 PoCdnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the…
- CVE-2002-06241 PoCBuffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE)…
- CVE-2002-06371 PoCInterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC…
- CVE-2002-06391 PoCInteger overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response…
- CVE-2002-06403 PoCsBuffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses…
- CVE-2002-06441 PoCBuffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000…
- CVE-2002-06471 PoCBuffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0…
- CVE-2002-06481 PoCThe legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read…
- CVE-2002-06493 PoCsMultiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote…
- CVE-2002-06521 PoCxfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly…
- CVE-2002-06531 PoCOff-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and…
- CVE-2002-06541 PoCApache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a…
- CVE-2002-06561 PoCBuffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a…
- CVE-2002-06581 PoCOSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link…
- CVE-2002-06591 PoCThe ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via…
- CVE-2002-06611 PoCDirectory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary…
- CVE-2002-06651 PoCMacromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.
- CVE-2002-06762 PoCsSoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to…
- CVE-2002-06801 PoCDirectory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded /…
- CVE-2002-06811 PoCCross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a…
- CVE-2002-06821 PoCCross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL…
- CVE-2002-06931 PoCBuffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT…
- CVE-2002-07021 PoCFormat string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the…
- CVE-2002-07081 PoCDirectory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary…
- CVE-2002-07091 PoCSQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary…
- CVE-2002-07211 PoCMicrosoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions,…
- CVE-2002-07231 PoCMicrosoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote…
- CVE-2002-07242 PoCsBuffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a…
- CVE-2002-07301 PoCCross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or…
- CVE-2002-07311 PoCCross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary script via a link…
- CVE-2002-07321 PoCCross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such…
- CVE-2002-07331 PoCCross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a…
- CVE-2002-07341 PoCb2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, which allows remote…
- CVE-2002-07371 PoCSambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a denial of service…
- CVE-2002-07402 PoCsBuffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges via a long -d…
- CVE-2002-07413 PoCspsyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a PASS command with a…
- CVE-2002-07471 PoCBuffer overflow in lsmcode in AIX 4.3.3.
- CVE-2002-07482 PoCsLabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that ends in two…
- CVE-2002-07491 PoCCGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-attachment field.
- CVE-2002-07641 PoCPhorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php…
- CVE-2002-07661 PoCOpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the…
- CVE-2002-07672 PoCssimpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child…
- CVE-2002-07691 PoCThe web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass authentication via…
- CVE-2002-07701 PoCQuake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and…
- CVE-2002-07711 PoCCross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1)…
- CVE-2002-07721 PoCDirectory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories…
- CVE-2002-07731 PoCimp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to…
- CVE-2002-07751 PoCbrowse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath…
- CVE-2002-07831 PoCOpera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites by setting the…
- CVE-2002-07861 PoCiCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary…
- CVE-2002-07871 PoCCross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote…
- CVE-2002-07933 PoCsHard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files…
- CVE-2002-07992 PoCsBuffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument.
- CVE-2002-08121 PoCInformation leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as…
- CVE-2002-08132 PoCsHeap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of…
- CVE-2002-08141 PoCBuffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute…
- CVE-2002-08161 PoCBuffer overflow in su in Tru64 Unix 5.x allows local users to gain root privileges via a long username and argument.
- CVE-2002-08171 PoCFormat string vulnerability in super for Linux allows local users to gain root privileges via a long command line argument.
- CVE-2002-08192 PoCsFormat string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a…
- CVE-2002-08201 PoCFreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the…
- CVE-2002-08231 PoCBuffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX…
- CVE-2002-08241 PoCBSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.
- CVE-2002-08331 PoCBuffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via…
- CVE-2002-08382 PoCsBuffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in…
- CVE-2002-08401 PoCCross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when…
- CVE-2002-08513 PoCsFormat string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to…
- CVE-2002-08552 PoCsCross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's…
- CVE-2002-08591 PoCBuffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary…
- CVE-2002-08622 PoCsThe (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft…
- CVE-2002-08661 PoCJava Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load…
- CVE-2002-08741 PoCVulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.
- CVE-2002-08751 PoCVulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to…
- CVE-2002-08762 PoCsWeb server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.
- CVE-2002-08791 PoCshowtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style pathname in the…
- CVE-2002-08861 PoCCisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via…
- CVE-2002-08871 PoCscoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary…
- CVE-2002-08921 PoCThe default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct…
- CVE-2002-08931 PoCDirectory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded…
- CVE-2002-08941 PoCNewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or…
- CVE-2002-08951 PoCBuffer overflow in MatuFtpServer 1.1.3.0 (1.1.3) allows remote attackers to cause a denial of service and possibly execute arbitrary code…
- CVE-2002-08971 PoCLocalWEB2000 2.1.0 web server allows remote attackers to bypass access restrictions for restricted files via a URL that contains the "/./"…
- CVE-2002-08981 PoCOpera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the client, via an…
- CVE-2002-09001 PoCBuffer overflow in pks PGP public key web server before 0.9.5 allows remote attackers to cause a denial of service (crash) and possibly…
- CVE-2002-09021 PoCCross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including…
- CVE-2002-09052 PoCsBuffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR environment variable.
- CVE-2002-09071 PoCBuffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the…
- CVE-2002-09081 PoCDirectory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary…
- CVE-2002-09092 PoCsMultiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local…
- CVE-2002-09131 PoCFormat string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on…
- CVE-2002-09181 PoCCGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the…
- CVE-2002-09192 PoCsCGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title…
- CVE-2002-09221 PoCCGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2)…
- CVE-2002-09231 PoCCGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or…
- CVE-2002-09261 PoCDirectory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via…
- CVE-2002-09281 PoCBuffer overflow in the Pirch 98 IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary code via a…
- CVE-2002-09312 PoCsCross-site scripting vulnerabilities in MyHelpDesk 20020509, and possibly other versions, allows remote attackers to execute script as…
- CVE-2002-09321 PoCSQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct…
- CVE-2002-09361 PoCThe Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a…
- CVE-2002-09371 PoCThe Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP…
- CVE-2002-09381 PoCCross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users…
- CVE-2002-09422 PoCsBuffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary code via long…
- CVE-2002-09461 PoCDirectory traversal vulnerability in SeaNox Devwex before 1.2002.0601 allows remote attackers to read arbitrary files via ..\ (dot dot)…
- CVE-2002-09481 PoCScripts For Educators MakeBook 2.2 CGI program allows remote attackers to execute script as other visitors, or execute server-side…
- CVE-2002-09491 PoCTelindus 1100 series ADSL router allows remote attackers to gain privileges to the device via a certain packet to UDP port 9833, which…
- CVE-2002-09511 PoCSQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the…
- CVE-2002-09531 PoCglobals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remote attackers to…
- CVE-2002-09551 PoCCross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to…
- CVE-2002-09591 PoCCross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag…
- CVE-2002-09611 PoCVulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other users, e.g. by…
- CVE-2002-09622 PoCsCross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url…
- CVE-2002-09641 PoCHalf-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to…
- CVE-2002-09652 PoCsBuffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute…
- CVE-2002-09681 PoCBuffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code…
- CVE-2002-09741 PoCHelp and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses…
- CVE-2002-09761 PoCInternet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource…
- CVE-2002-09801 PoCThe Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which…
- CVE-2002-09821 PoCMicrosoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter…
- CVE-2002-09871 PoCX server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which…
- CVE-2002-09912 PoCsBuffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to…
- CVE-2002-09941 PoCSunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte…
- CVE-2002-09951 PoClogin.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to…