Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-2420 Improper Input Validation vulnerability in Independent Solution Simple Site Searcher and Super Site Searcher
site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
network
low complexity
independent-solution CWE-20
7.5
2002-12-31 CVE-2002-2415 Improper Input Validation vulnerability in Alliedtelesyn At-8024 and Rapier 24
Allied Telesyn AT-8024 1.3.1 and Rapier 24 switches allow remote authenticated users to cause a denial of service in the management interface via a stream of zero (null) bytes sent via UDP to a running service.
network
low complexity
alliedtelesyn CWE-20
6.8
2002-12-31 CVE-2002-2406 Improper Input Validation vulnerability in Perception Liteserve 2.0/2.0.1/2.0.2
Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request.
network
low complexity
perception CWE-20
5.0
2002-12-31 CVE-2002-2393 Improper Input Validation vulnerability in Solarwinds Serv-U File Server 3.1.0.0/4.0.0.4
Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.
network
low complexity
solarwinds CWE-20
5.0
2002-12-31 CVE-2002-2371 Improper Input Validation vulnerability in Linksys Wet11 1.31/1.32
Linksys WET11 firmware 1.31 and 1.32 allows remote attackers to cause a denial of service (crash) via a packet containing the device's hardware address as the source MAC address in the DLC header.
network
low complexity
linksys CWE-20
7.8
2002-12-31 CVE-2002-2365 Improper Input Validation vulnerability in Springer Verlag Berlin Heidelberg Simple Wais 1.11
Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.
network
low complexity
springer-verlag-berlin-heidelberg CWE-20
critical
10.0
2002-12-31 CVE-2002-2354 Improper Input Validation vulnerability in Netgear Fm114P
Netgear FM114P firmware 1.3 wireless firewall allows remote attackers to cause a denial of service (crash or hang) via a large number of TCP connection requests.
network
low complexity
netgear CWE-20
7.8
2002-12-31 CVE-2002-2338 Improper Input Validation vulnerability in multiple products
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
network
low complexity
mozilla netscape CWE-20
5.0
2002-12-31 CVE-2002-2329 Improper Input Validation vulnerability in Mirabilis ICQ 2001B/2002A/2002B
ICQ client 2001b, 2002a and 2002b allows remote attackers to cause a denial of service (CPU consumption or crash) via a message with a large number of emoticons.
network
low complexity
mirabilis CWE-20
7.8
2002-12-31 CVE-2002-2328 Improper Input Validation vulnerability in Microsoft Windows 2000
Active Directory in Windows 2000, when supporting Kerberos V authentication and GSSAPI, allows remote attackers to cause a denial of service (hang) via an LDAP client that sets the page length to zero during a large request.
network
microsoft CWE-20
7.1