CVE Database - 2002

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

110
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2002-0495

HIGH
10.00 CVSS 2.0

csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.

Code Injection
WAF: Medium

CVE-2002-0507

LOW
2.10 CVSS 2.0

An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

Improper Authentication
WAF: Low

CVE-2002-0563

MEDIUM
5.00 CVSS 2.0

The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.

Improper Authentication
WAF: Low

CVE-2002-0146

MEDIUM
5.00 CVSS 2.0

fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite memory via a message count that exceeds the boundaries of an array.

Improper Input Validation
WAF: Medium

CVE-2002-0367

HIGH
7.80 CVSS 3.1

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

Improper Privilege Management
WAF: Low

CVE-2002-0368

MEDIUM
5.00 CVSS 2.0

The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."

Uncontrolled Resource Consumption
WAF: Medium

CVE-2002-0270

MEDIUM
4.30 CVSS 2.0

Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.

Cross-Site Scripting (XSS)
WAF: High

CVE-2002-0061

HIGH
7.50 CVSS 2.0

Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.

OS Command Injection
WAF: High

CVE-2002-0080

LOW
2.10 CVSS 2.0

rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.

Improper Privilege Management
WAF: Low

CVE-2002-0049

MEDIUM
6.40 CVSS 2.0

Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.

Improper Privilege Management
WAF: Low
Page 3 of 3 (110 CVEs)