Total
286246 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2002-0463 | 1 Arsc Really Simple Chat | 1 Arsc Really Simple Chat | 2024-11-20 | N/A |
home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message. | ||||
CVE-2002-0462 | 1 Big Sam | 1 Big Sam | 2024-11-20 | N/A |
bigsam_guestbook.php for Big Sam (Built-In Guestbook Stand-Alone Module) 1.1.08 and earlier allows remote attackers to cause a denial of service (CPU consumption) or obtain the absolute path of the web server via a displayBegin parameter with a very large number, which leaks the web path in an error message when PHP safe_mode is enabled, or consumes resources when safe_mode is not enabled. | ||||
CVE-2002-0461 | 1 Microsoft | 1 Internet Explorer | 2024-11-20 | N/A |
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop. | ||||
CVE-2002-0460 | 1 Bitvise | 1 Winsshd | 2024-11-20 | N/A |
Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of incomplete connections that are not properly terminated, which are not properly freed by SSHd. | ||||
CVE-2002-0459 | 1 Linux-sottises | 2 Board-tnk, News-tnk | 2024-11-20 | N/A |
Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter. | ||||
CVE-2002-0458 | 1 Linux-sottises | 1 News-tnk | 2024-11-20 | N/A |
Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter. | ||||
CVE-2002-0457 | 1 Bg Guestbook | 1 Bg Guestbook | 2024-11-20 | N/A |
Cross-site scripting vulnerability in signgbook.php for BG GuestBook 1.0 allows remote attackers to execute arbitrary Javascript via encoded tags such as <, >, and & in fields such as (1) name, (2) email, (3) AIM screen name, (4) website, (5) location, or (6) message. | ||||
CVE-2002-0456 | 1 Qualcomm | 1 Eudora | 2024-11-20 | N/A |
Eudora 5.1 and earlier versions stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames. | ||||
CVE-2002-0455 | 1 Incredimail | 1 Incredimail | 2024-11-20 | N/A |
IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames. | ||||
CVE-2002-0454 | 1 Qualcomm | 1 Qpopper | 2024-11-20 | N/A |
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop. | ||||
CVE-2002-0453 | 1 Oblix | 1 Netpoint | 2024-11-20 | N/A |
The account lockout capability in Oblix NetPoint 5.2 and earlier only locks out users once for the specified lockout period, which makes it easier for remote attackers to conduct brute force password guessing by waiting until the lockout period ends, then guessing passwords without being locked out again. | ||||
CVE-2002-0452 | 1 Foundrynet | 1 Serveriron | 2024-11-20 | N/A |
Foundry Networks ServerIron switches do not decode URIs when applying "url-map" rules, which could make it easier for attackers to cause the switch to forward traffic to a different server than intended and exploit vulnerabilities that would otherwise be inaccessible. | ||||
CVE-2002-0451 | 1 Phpprojekt | 1 Phpprojekt | 2024-11-20 | N/A |
filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_path parameter. | ||||
CVE-2002-0450 | 1 Talentsoft | 1 Web\+ Server | 2024-11-20 | N/A |
Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe. | ||||
CVE-2002-0449 | 1 Talentsoft | 1 Web\+ Server | 2024-11-20 | N/A |
Buffer overflow in webpsvc.exe for Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long argument to webplus.exe program, which triggers the overflow in webpsvc.exe. | ||||
CVE-2002-0448 | 1 Xerver | 1 Xerver | 2024-11-20 | N/A |
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences. | ||||
CVE-2002-0447 | 1 Xerver | 1 Xerver | 2024-11-20 | N/A |
Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in an HTTP GET request. | ||||
CVE-2002-0446 | 1 Black Tie Project | 1 Black Tie Project | 2024-11-20 | N/A |
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message. | ||||
CVE-2002-0445 | 1 Php Firstpost | 1 Php Firstpost | 2024-11-20 | N/A |
article.php in PHP FirstPost 0.1 allows allows remote attackers to obtain the full pathname of the server via an invalid post number in the post parameter, which leaks the pathname in an error message. | ||||
CVE-2002-0444 | 1 Microsoft | 1 Windows 2000 Terminal Services | 2024-11-20 | N/A |
Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies. |