Unknown · CVSS Not scored
Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot dot) attack in the requested URL.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program for encrypting passwords, which could allow local users to break all user passwords by cracking the key or modifying a copy of the sambar program to call the decryption procedure.
Published Apr 2, 2003 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.
Published Sep 1, 2004 · Updated Aug 8, 2024
Unknown · CVSS Not scored
qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames on the system.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in muxatmd in AIX 4 allows an attacker to cause a core dump and possibly execute code.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then setting the descriptor to NULL via a close in another process that is created via rfork.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.
Published Sep 1, 2004 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Webridge PX Application Suite allows remote attackers to obtain sensitive information via a malformed request that generates a server error message, which includes full pathname or internal IP address information in the variables (1) APPL_PHYSICAL_PATH, (2) PATH_TRANSLATED, and (3) LOCAL_ADDR.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IRC DCC helper in the ip_masq_irc IP masquerading module 2.2 allows remote attackers to bypass intended firewall restrictions by causing the target system to send a "DCC SEND" request to a malicious server which listens on port 6667, which may cause the module to believe that the traffic is a valid request and allow the connection to the port specified in the DCC SEND request.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbitrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
Published Mar 9, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does not check login credentials for upload operations, which allows remote attackers to copy and upload arbitrary files and read the PHP-Nuke configuration file by directly calling admin.php with an upload parameter and specifying the file to copy.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
AdLogin.pm in AdCycle 1.15 and earlier allows remote attackers to bypass authentication and gain privileges by injecting SQL code in the $password argument.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.
Published Feb 2, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
Published Mar 9, 2002 · Updated Aug 8, 2024