Show filters
486 Total Results
Displaying 421-430 of 486
Sort by:
Attacker Value
Unknown

CVE-2002-0656

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
0
Attacker Value
Unknown

CVE-2002-0655

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2002-0392

Disclosure Date: July 03, 2002 (last updated October 03, 2023)
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
0
Attacker Value
Unknown

CVE-2002-0304

Disclosure Date: May 31, 2002 (last updated February 22, 2025)
Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.
0
Attacker Value
Unknown

CVE-2002-0249

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.
0
Attacker Value
Unknown

CVE-2002-0257

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.
0
Attacker Value
Unknown

CVE-2002-0240

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.
0
Attacker Value
Unknown

CVE-2002-1592

Disclosure Date: May 06, 2002 (last updated February 22, 2025)
The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2002-0061

Disclosure Date: March 21, 2002 (last updated February 22, 2025)
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
0
Attacker Value
Unknown

CVE-2001-1534

Disclosure Date: December 31, 2001 (last updated February 22, 2025)
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
0