CVE-2002-1000 to CVE-2002-1999
267 CVEs with public proof-of-concept exploits.
- CVE-2002-10011 PoCBuffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via…
- CVE-2002-10041 PoCDirectory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to…
- CVE-2002-10061 PoCCross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote…
- CVE-2002-10071 PoCCross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id…
- CVE-2002-10081 PoCCross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute…
- CVE-2002-10091 PoCCross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute…
- CVE-2002-10131 PoCBuffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Media-IXT 3.0.4…
- CVE-2002-10141 PoCBuffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary…
- CVE-2002-10161 PoCAdobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files,…
- CVE-2002-10211 PoCBadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.
- CVE-2002-10231 PoCBadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.
- CVE-2002-10271 PoCCross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows…
- CVE-2002-10281 PoCMultiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of…
- CVE-2002-10291 PoCRes Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to…
- CVE-2002-10311 PoCKeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00…
- CVE-2002-10331 PoCDirectory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:"…
- CVE-2002-10341 PoCnone.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument.
- CVE-2002-10361 PoCCross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to…
- CVE-2002-10421 PoCDirectory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when…
- CVE-2002-10431 PoCUltrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").
- CVE-2002-10481 PoCHP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP…
- CVE-2002-10513 PoCsFormat string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T…
- CVE-2002-10572 PoCsBuffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command.
- CVE-2002-10581 PoCDirectory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as…
- CVE-2002-10594 PoCsBuffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code…
- CVE-2002-10601 PoCCross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway…
- CVE-2002-10692 PoCsThe remote administration capability for the D-Link DI-804 router 4.68 allows remote attackers to bypass authentication and release DHCP…
- CVE-2002-10701 PoCCross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via…
- CVE-2002-10711 PoCZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet…
- CVE-2002-10721 PoCZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized,…
- CVE-2002-10732 PoCsBuffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.
- CVE-2002-10751 PoCBuffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2002-10764 PoCsBuffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long…
- CVE-2002-10771 PoCIPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request…
- CVE-2002-10791 PoCDirectory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash)…
- CVE-2002-10891 PoCrwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable…
- CVE-2002-10911 PoCNetscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image…
- CVE-2002-11011 PoCCisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user…
- CVE-2002-11131 PoCsummary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the…
- CVE-2002-11206 PoCsBuffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2002-11233 PoCsBuffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote…
- CVE-2002-11254 PoCsFreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and…
- CVE-2002-11291 PoCBuffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.
- CVE-2002-11313 PoCsCross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via…
- CVE-2002-11321 PoCSquirrelMail 1.2.7 and earlier allows remote attackers to determine the absolute pathname of the options.php script via a malformed…
- CVE-2002-11351 PoCmodsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an…
- CVE-2002-11422 PoCsHeap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and…
- CVE-2002-11432 PoCsMicrosoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when…
- CVE-2002-11471 PoCThe HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration…
- CVE-2002-11481 PoCThe default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read…
- CVE-2002-11552 PoCsBuffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.
- CVE-2002-11651 PoCSendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998,…
- CVE-2002-11671 PoCCross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote…
- CVE-2002-11681 PoCCross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote…
- CVE-2002-11691 PoCIBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via…
- CVE-2002-11781 PoCDirectory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary…
- CVE-2002-11791 PoCBuffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary…
- CVE-2002-11831 PoCMicrosoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to…
- CVE-2002-11871 PoCCross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the…
- CVE-2002-11921 PoCMultiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to…
- CVE-2002-12091 PoCDirectory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files…
- CVE-2002-12111 PoCPrometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to…
- CVE-2002-12141 PoCBuffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and…
- CVE-2002-12153 PoCsMultiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers…
- CVE-2002-12171 PoCCross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute…
- CVE-2002-12201 PoCBIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a…
- CVE-2002-12221 PoCBuffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a…
- CVE-2002-12241 PoCDirectory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user…
- CVE-2002-12308 PoCsNetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as…
- CVE-2002-12361 PoCThe remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a…
- CVE-2002-12381 PoCPeter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request…
- CVE-2002-12391 PoCQNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which…
- CVE-2002-12421 PoCSQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the…
- CVE-2002-12481 PoCNorthern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of…
- CVE-2002-12501 PoCBuffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument.
- CVE-2002-12541 PoCInternet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system…
- CVE-2002-12751 PoCUnknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code…
- CVE-2002-12961 PoCDirectory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences…
- CVE-2002-13071 PoCCross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email…
- CVE-2002-13171 PoCBuffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial…
- CVE-2002-13181 PoCBuffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via…
- CVE-2002-13201 PoCPine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email message with a From…
- CVE-2002-13221 PoCRational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain…
- CVE-2002-13342 PoCsCross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script…
- CVE-2002-13373 PoCsBuffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related…
- CVE-2002-13491 PoCBuffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to…
- CVE-2002-13511 PoCBuffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute…
- CVE-2002-13593 PoCsMultiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial…
- CVE-2002-13612 PoCsoverflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary…
- CVE-2002-13642 PoCsBuffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.
- CVE-2002-13681 PoCCommon Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2002-13741 PoCThe COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute…
- CVE-2002-13751 PoCThe COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long…
- CVE-2002-13801 PoCLinux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to…
- CVE-2002-13811 PoCFormat string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute…
- CVE-2002-14051 PoCCRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is…
- CVE-2002-14101 PoCEasy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access…
- CVE-2002-14121 PoCGallery photo album package before 1.3.1 allows local and possibly remote attackers to execute arbitrary code via a modified…
- CVE-2002-14141 PoCBuffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable.
- CVE-2002-14221 PoCadmbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest…
- CVE-2002-14231 PoCtmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter.
- CVE-2002-14261 PoCHP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85…
- CVE-2002-14271 PoCThe print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers…
- CVE-2002-14281 PoCindex.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to…
- CVE-2002-14291 PoCCross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox…
- CVE-2002-14321 PoCMidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information…
- CVE-2002-14341 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML…
- CVE-2002-14351 PoCclass.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the…
- CVE-2002-14361 PoCThe web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST…
- CVE-2002-14441 PoCThe Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with…
- CVE-2002-14451 PoCCross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a…
- CVE-2002-14471 PoCBuffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long…
- CVE-2002-14512 PoCsBlazix before 1.2.2 allows remote attackers to read source code of JSP scripts or list restricted web directories via an HTTP request that…
- CVE-2002-14521 PoCBuffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget…
- CVE-2002-14531 PoCCross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request…
- CVE-2002-14552 PoCsMultiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1)…
- CVE-2002-14561 PoCBuffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.
- CVE-2002-14571 PoCSQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search…
- CVE-2002-14631 PoCSymantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor Models 500/700/1000 and 1100/1200/1300, and…
- CVE-2002-14681 PoCBuffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
- CVE-2002-14691 PoCscponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated…
- CVE-2002-14733 PoCsMultiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly…
- CVE-2002-14801 PoCCross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook…
- CVE-2002-14811 PoCsavesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or…
- CVE-2002-14821 PoCSQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain…
- CVE-2002-14831 PoCdb4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument…
- CVE-2002-14841 PoCDB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections…
- CVE-2002-14865 PoCsMultiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service…
- CVE-2002-14872 PoCsThe IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw…
- CVE-2002-14881 PoCThe IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message…
- CVE-2002-14891 PoCBuffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with…
- CVE-2002-14922 PoCsBuffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to…
- CVE-2002-14931 PoCCross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE…
- CVE-2002-14941 PoCCross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the…
- CVE-2002-14951 PoCCross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached…
- CVE-2002-14961 PoCHeap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in…
- CVE-2002-14971 PoCCross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a…
- CVE-2002-14991 PoCMultiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the…
- CVE-2002-15011 PoCThe MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of…
- CVE-2002-15031 PoCBuffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long MON_WORK_DIR…
- CVE-2002-15051 PoCSQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the…
- CVE-2002-15063 PoCsBuffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG environment variable,…
- CVE-2002-15121 PoCxbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the…
- CVE-2002-15131 PoCThe UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile…
- CVE-2002-15142 PoCsgds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X"…
- CVE-2002-15223 PoCsBuffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and…
- CVE-2002-15251 PoCDirectory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary…
- CVE-2002-15261 PoCCross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via…
- CVE-2002-15271 PoCemumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing…
- CVE-2002-15291 PoCCross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email…
- CVE-2002-15301 PoCThe administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext…
- CVE-2002-15331 PoCCross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an…
- CVE-2002-15391 PoCBuffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE…
- CVE-2002-15421 PoCSolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly…
- CVE-2002-15493 PoCsBuffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2002-15591 PoCDirectory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or…
- CVE-2002-15601 PoCindex.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter…
- CVE-2002-15614 PoCsThe RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC…
- CVE-2002-15661 PoCnetris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to cause a denial of…
- CVE-2002-15671 PoCCross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies…
- CVE-2002-15701 PoCHeap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code…
- CVE-2002-15761 PoClserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which allows local users…
- CVE-2002-15801 PoCInteger overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length…
- CVE-2002-15811 PoCDirectory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files…
- CVE-2002-16021 PoCBuffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.
- CVE-2002-16031 PoCGoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f…
- CVE-2002-16051 PoCBuffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET…
- CVE-2002-16142 PoCsBuffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.
- CVE-2002-16161 PoCMultiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh,…
- CVE-2002-16341 PoCNovell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2)…
- CVE-2002-16434 PoCsMultiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1)…
- CVE-2002-16521 PoCBuffer overflow in cgicso.c for cgiemail 1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2002-16561 PoCX-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via…
- CVE-2002-16601 PoCcalendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command…
- CVE-2002-16631 PoCThe Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via…
- CVE-2002-16731 PoCThe web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the interface, which allows…
- CVE-2002-16831 PoCCross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other…
- CVE-2002-16851 PoCCross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to…
- CVE-2002-16881 PoCThe browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other…
- CVE-2002-17001 PoCCross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute…
- CVE-2002-17021 PoCCross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitrary script as…
- CVE-2002-17031 PoCCross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute arbitrary script as…
- CVE-2002-17041 PoCZeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP…
- CVE-2002-17051 PoCMicrosoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS)…
- CVE-2002-17081 PoCCross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by…
- CVE-2002-17122 PoCsMicrosoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP…
- CVE-2002-17141 PoCMicrosoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html"…
- CVE-2002-17151 PoCSSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script…
- CVE-2002-17201 PoCSQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain privileges via the…
- CVE-2002-17271 PoCCross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to…
- CVE-2002-17311 PoCThe System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF.
- CVE-2002-17401 PoCBuffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute…
- CVE-2002-17411 PoCDirectory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users…
- CVE-2002-17441 PoCDirectory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the…
- CVE-2002-17571 PoCPHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for…
- CVE-2002-17621 PoCMicrosoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans…
- CVE-2002-17661 PoCBuffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with…
- CVE-2002-17671 PoCBuffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as the oracle user…
- CVE-2002-17731 PoCBuffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and possibly execute…
- CVE-2002-17851 PoCCross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated…
- CVE-2002-17901 PoCThe SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and…
- CVE-2002-17922 PoCsBuffer overflow in Fake Identd 0.9 through 1.4 allows remote attackers to execute arbitrary code as root via a long request that is split…
- CVE-2002-17982 PoCsMidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or…
- CVE-2002-17991 PoCCross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) email…
- CVE-2002-18021 PoCCross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML via Javascript in…
- CVE-2002-18031 PoCCross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in…
- CVE-2002-18041 PoCCross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via Javascript in an…
- CVE-2002-18051 PoCCross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in…
- CVE-2002-18061 PoCCross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in…
- CVE-2002-18091 PoCThe default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote…
- CVE-2002-18111 PoCBelkin F5D6130 Wireless Network Access Point running firmware AP14G8 allows remote attackers to cause a denial of service (connection…
- CVE-2002-18121 PoCBuffer overflow in gdam123 0.933 and 0.942 allows local users to execute arbitrary code via a long filename parameter.
- CVE-2002-18131 PoCDirectory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by…
- CVE-2002-18144 PoCsBuffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.
- CVE-2002-18161 PoCOff-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute…
- CVE-2002-18181 PoCezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSite parameter.
- CVE-2002-18231 PoCBuffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP…
- CVE-2002-18261 PoCgrsecurity 1.9.4 for Linux kernel 2.4.18 allows local users to bypass read-only permissions by using mmap to directly map /dev/mem or…
- CVE-2002-18273 PoCsSendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map,…
- CVE-2002-18281 PoCSavant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length…
- CVE-2002-18291 PoCCross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject…
- CVE-2002-18301 PoCOpen Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request…
- CVE-2002-18311 PoCMicrosoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that…
- CVE-2002-18371 PoCThe getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of…
- CVE-2002-18451 PoCCross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject…
- CVE-2002-18471 PoCBuffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary…
- CVE-2002-18501 PoCmod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory…
- CVE-2002-18521 PoCCross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or…
- CVE-2002-18621 PoCSmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all…
- CVE-2002-18642 PoCsDirectory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a…
- CVE-2002-18651 PoCBuffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys…
- CVE-2002-18661 PoCSimple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to…
- CVE-2002-18681 PoCDispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields.
- CVE-2002-18701 PoCSimple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers…
- CVE-2002-18781 PoCPHP remote file inclusion vulnerability in w-Agora 4.1.3 allows remote attackers to execute arbitrary PHP code via the inc_dir parameter.
- CVE-2002-18841 PoCindex.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin".
- CVE-2002-18851 PoCPHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to…
- CVE-2002-18861 PoCTightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain…
- CVE-2002-18872 PoCsPHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code…
- CVE-2002-18911 PoCBuffer overflow in IRCIT 0.3.1 IRC client allows remote attackers to execute arbitrary code via a long invite request.
- CVE-2002-18961 PoCBuffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a long (1) -f or (2)…
- CVE-2002-18971 PoCMyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, possibly…
- CVE-2002-18981 PoCTerminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link,…
- CVE-2002-19042 PoCsBuffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a…
- CVE-2002-19051 PoCBuffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (crash) via a long…
- CVE-2002-19061 PoCThe web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) by sending…
- CVE-2002-19071 PoCTelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
- CVE-2002-19101 PoCClick2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows…
- CVE-2002-19111 PoCZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory…
- CVE-2002-19221 PoCCross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject…
- CVE-2002-19291 PoCCross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject…
- CVE-2002-19301 PoCBuffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.
- CVE-2002-19431 PoCSafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a response to a…
- CVE-2002-19451 PoCBuffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP…
- CVE-2002-19511 PoCBuffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number…
- CVE-2002-19542 PoCsCross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or…
- CVE-2002-19581 PoCCross-site scripting (XSS) vulnerability in kmMail 1.0, 1.0a, and 1.0b allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2002-19651 PoCCross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to inject arbitrary web…
- CVE-2002-19661 PoCDirectory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read arbitrary files…
- CVE-2002-19731 PoCBuffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static…
- CVE-2002-19821 PoCDirectory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory…
- CVE-2002-19831 PoCThe timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by…
- CVE-2002-19861 PoCPerception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a…
- CVE-2002-19911 PoCPHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.
- CVE-2002-19931 PoCwebbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.
- CVE-2002-19951 PoCCross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2002-19982 PoCsBuffer overflow in rpc.cmsd in SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows remote attackers to execute arbitrary commands via a long…