Unknown · CVSS Not scored
Oracle listener in Oracle 8i on Solaris allows remote attackers to cause a denial of service via a malformed connection packet with a maximum transport data size that is set to 0.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnerability.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
GoodTech FTP server 3.0.1.2.1.0 and earlier allows remote attackers to cause a denial of service via a flood of connections to the server, which causes it to crash.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many "/../" (dot dot) sequences.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in pi program in PlanetIntra 2.5 allows remote attackers to execute arbitrary commands.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.
Published Mar 9, 2001 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.
Published Mar 9, 2001 · Updated Aug 8, 2024