Total
29527 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2002-1887 | 1 Gregory Kokanosky | 1 Phpmynewsletter | 2008-09-05 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter. | |||||
CVE-2002-1950 | 1 Phprank | 1 Phprank | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list. | |||||
CVE-2002-1786 | 1 Sgi | 1 Irix | 2008-09-05 | 2.1 LOW | N/A |
SGI IRIX 6.5 through 6.5.14 applies a umask of 022 to root core dumps, which allows local users to read the core dumps and possibly obtain sensitive information. | |||||
CVE-2002-1926 | 1 Aquonics Scripting | 1 Aquonics File Manager | 2008-09-05 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in source.php in Aquonics File Manager 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP query string. | |||||
CVE-2002-1936 | 1 Utstarcom | 1 Bas 1000 | 2008-09-05 | 7.5 HIGH | N/A |
UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field", (2) guru account with a password of "*3noguru", (3) snmp account with a password of "snmp", or (4) dbase account with a password of "dbase". | |||||
CVE-2002-1907 | 1 Telcondex | 1 Simplewebserver | 2008-09-05 | 5.0 MEDIUM | N/A |
TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. | |||||
CVE-2002-1967 | 1 Mark Hanson | 1 Xircon | 2008-09-05 | 5.0 MEDIUM | N/A |
Buffer overflow in XiRCON 1.0 Beta 4 allows remote attackers to cause a denial of service (disconnect) via a long (1) ctcp, (2) primsg, (3) msg, or (4) notice command. | |||||
CVE-2002-1956 | 1 Rox | 1 Filer | 2008-09-05 | 2.1 LOW | N/A |
ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files. | |||||
CVE-2002-1837 | 1 Ids | 1 Ids | 2008-09-05 | 5.0 MEDIUM | N/A |
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not. | |||||
CVE-2002-1896 | 1 Alsaplayer | 1 Alsaplayer | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a long (1) -f or (2) -o command line argument. | |||||
CVE-2002-1939 | 1 Flashfxp | 1 Flashfxp | 2008-09-05 | 2.1 LOW | N/A |
FlashFXP 1.4 prints FTP passwords in plaintext when there are transfers in the queue, which allows attackers to obtain FTP passwords of other users by editing the queue properties. | |||||
CVE-2002-1900 | 1 Pinboard | 1 Pinboard | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists. | |||||
CVE-2002-1849 | 1 Parachat | 1 Parachat Server | 2008-09-05 | 5.0 MEDIUM | N/A |
ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users. | |||||
CVE-2002-1972 | 1 Sebastian Dehne | 1 Pp Powerswitch | 2008-09-05 | 4.6 MEDIUM | N/A |
Unknown vulnerability in Parallel port powerSwitch (aka pp_powerSwitch) 0.1 does not properly enforce access controls, which allows local users to access arbitrary ports. | |||||
CVE-2002-1947 | 1 Webmin | 1 Webmin | 2008-09-05 | 6.4 MEDIUM | N/A |
Webmin 0.21 through 1.0 uses the same built-in SSL key for all installations, which allows remote attackers to eavesdrop or highjack the SSL session. | |||||
CVE-2002-1831 | 1 Microsoft | 1 Msn Messenger | 2008-09-05 | 5.0 MEDIUM | N/A |
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field. | |||||
CVE-2002-1929 | 1 Php Arena | 1 Pafiledb | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary web script or HTML via the query string in the (1) rate, (2) email, or (3) download actions. | |||||
CVE-2002-1825 | 1 Wasd | 1 Wasd Http Server | 2008-09-05 | 6.4 MEDIUM | N/A |
Format string vulnerability in PerlRTE_example1.pl in WASD 7.1, 7.2.0 through 7.2.3, and 8.0.0 allows remote attackers to execute arbitrary commands or crash the server via format strings in the $name variable. | |||||
CVE-2002-1835 | 1 Xerox | 2 Docutech 6110, Docutech 6115 | 2008-09-05 | 7.5 HIGH | N/A |
The default configuration of Xerox DocuTech 6110 and DocuTech 6115 running Solaris 8.0 has a large number of unnecessary services enabled such as RPC and sprayd, which could allow remote attackers to obtain access to the device. | |||||
CVE-2002-1863 | 1 Iomega | 1 Network Attached Storage | 2008-09-05 | 4.6 MEDIUM | N/A |
Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled. |