Show filters
486 Total Results
Displaying 411-420 of 486
Sort by:
Attacker Value
Unknown

CVE-2002-0843

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
0
Attacker Value
Unknown

CVE-2002-1156

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.
0
Attacker Value
Unknown

CVE-2002-0839

Disclosure Date: October 11, 2002 (last updated October 03, 2023)
The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
0
Attacker Value
Unknown

CVE-2002-0840

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
0
Attacker Value
Unknown

CVE-2002-1008

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.
0
Attacker Value
Unknown

CVE-2002-1009

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.
0
Attacker Value
Unknown

CVE-2002-1593

Disclosure Date: September 25, 2002 (last updated February 22, 2025)
mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
0
Attacker Value
Unknown

CVE-2002-0654

Disclosure Date: September 05, 2002 (last updated February 22, 2025)
Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when a script (child process) cannot be invoked.
0
Attacker Value
Unknown

CVE-2002-0659

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
0
Attacker Value
Unknown

CVE-2002-0661

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
0