NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
79430  CVE-2002-0424  efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.    4.6  Medium  2017-01-05  2008-09-05  View
79429  CVE-2002-0423  Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup.    10  High  2017-01-05  2008-09-05  View
79428  CVE-2002-0422  IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header.    2.6  Low  2017-01-05  2016-10-17  View
79427  CVE-2002-0421  IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.    Medium  2017-01-05  2008-09-05  View
79426  CVE-2002-0420  Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions.    7.5  High  2017-01-05  2008-09-05  View

Page 16721 of 17672, showing 5 records out of 88360 total, starting on record 83601, ending on 83605

Actions