Unknown · CVSS Not scored
GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".
Published May 3, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which could allow remote attackers to steal the passwords via sniffing.
Published May 3, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.
Published May 3, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.
Published May 3, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.
Published May 3, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.
Published May 3, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
myphpPagetool PHP script 0.4.3-1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
Published Apr 18, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
GroupWise 5.5 and 6 running in live remote or smart caching mode allows remote attackers to read arbitrary users' mailboxes by extracting usernames and passwords from sniffed network traffic, as addressed by the "Padlock" fix.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
PowerNet IX allows remote attackers to cause a denial of service via a port scan.
Published May 3, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.
Published May 3, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Bharat Mediratta Gallery PHP script before 1.2.1 allows remote attackers to execute arbitrary code by including files from remote web sites via an HTTP request that modifies the includedir variable.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.
Published Sep 1, 2004 · Updated Aug 8, 2024
Unknown · CVSS Not scored
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflow in Elm 2.5.5 and earlier allows remote attackers to execute arbitrary code via a long Message-ID header.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in EFTP 2.0.8.346 allows local users to read directories via a ... (modified dot dot) in the CWD command.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Format string vulnerability in gpm-root in gpm 1.17.8 through 1.17.18 allows local users to gain root privileges.
Published Jun 25, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.
Published Mar 15, 2002 · Updated Aug 8, 2024
Unknown · CVSS Not scored
mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the sendto, email, server, subject, and resulturl hidden form fields.
Published Mar 15, 2002 · Updated Aug 8, 2024