NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
79430 | CVE-2002-0424 | efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
79429 | CVE-2002-0423 | Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup. | 2 | 10 | High | 2017-01-05 | 2008-09-05 | View | |
79428 | CVE-2002-0422 | IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header. | 2 | 2.6 | Low | 2017-01-05 | 2016-10-17 | View | |
79427 | CVE-2002-0421 | IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
79426 | CVE-2002-0420 | Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View |
Page 16721 of 17672, showing 5 records out of 88360 total, starting on record 83601, ending on 83605