| OSVDB ID | Disclosure Date | Title |
|
43172
Description:
Unknown / Incomplete
|
2002-10-31
|
Duplicity rdiffdir Patch Traversal Arbitrary File Overwrite
|
|
8939
Description:
(Description Provided by CVE) : Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information.
|
2002-10-31
|
Cisco ONS Default Public Hardcoded SNMP String
|
|
61292
Description:
Unknown / Incomplete
|
2002-10-31
|
t-prot (TOFU Protection) for Mutt Symlink Arbitrary File Overwrite
|
|
4013
Description:
A remote overflow exists in Oracle Database 9i. Oracle Database 9i fails to handle an overly long user ID parameter resulting in a buffer overflow. With a specially crafted request, an attacker can cause arbitrary code to run in the security context of the web server resulting in a loss of confidentiality, integrity, and/or availability.
|
2002-10-31
|
Oracle iSQL*Plus isqlplus URL USERID Parameter Remote Overflow
|
|
6244
Description:
PHP-Nuke contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the bio variable in the administrative module is not verified properly and will allow an attacker to inject or manipulate SQL queries.
|
2002-10-31
|
PHP-Nuke modules.php bio Parameter SQL Injection
|
|
6740
Description:
(Description Provided by CVE) : The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote attackers to cause a denial of service (crash) via an HTTP request to Gozila.cgi without any arguments.
|
2002-10-31
|
Linksys BEFSR41 Gozila.cgi No Argument Remote DoS
|
|
7359
Description:
(Description Provided by CVE) : Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.
|
2002-10-31
|
thttpd Host: Header Traversal Arbitrary File Access
|
|
8551
Description:
Merak Email Server contains a flaw related to authentication that may allow an attacker to login without an email address. No further details have been provided.
|
2002-10-31
|
IceWarp WebMail EmailLogin Issue
|
|
8879
Description:
(Description Provided by CVE) : Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist.
|
2002-10-31
|
Cisco ONS FTP TCC/XTC Invalid Authentication System Modification
|
|
8924
Description:
(Description Provided by CVE) : Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.
|
2002-10-31
|
Cisco ONS Image Database/Backup Password Disclosure
|
|
8925
Description:
(Description Provided by CVE) : Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR).
|
2002-10-31
|
Cisco ONS HTTP Invalid CORBA IOR DoS
|
|
8926
Description:
(Description Provided by CVE) : Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.
|
2002-10-31
|
Cisco ONS Malformed HTTP Request DoS
|
|
8927
Description:
(Description Provided by CVE) : Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet.
|
2002-10-31
|
Cisco ONS VxWorks Operating System Default Account
|
|
12643
Description:
(Description Provided by CVE) : runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments.
|
2002-10-31
|
LPRng runlpr Command Line Overflow
|
|
14495
Description:
(Description Provided by CVE) : Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE that points to code stored on a remote server, which is then used in (1) index.php, (2) install.php, or (3) various test_*.php scripts.
|
2002-10-31
|
Prometheus all.lib PHP Code Execution
|
|
17124
Description:
(Description Provided by CVE) : IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.
|
2002-10-31
|
Microsoft IIS Malformed WebDAV Request DoS
|
|
59527
Description:
(Description Provided by CVE) : Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SMTP) or (2) TCP port 110 (POP3).
|
2002-10-31
|
SmartMail Server Multiple Port Request Handling Remote Overflow DoS
|
|
59881
Description:
(Description Provided by CVE) : SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.
|
2002-10-31
|
SmartMail Server Incomplete Data Connection Remote DoS
|
|
5346
Description:
(Description Provided by CVE) : uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands.
|
2002-10-30
|
sharutils uudecode Link/Pipe Arbitrary Command Execution
|
|
58668
Description:
Unknown / Incomplete
|
2002-10-30
|
Apache Axis External Entity (XXE) Data Parsing Privilege Escalation
|
|
13438
Description:
(Description Provided by CVE) : The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
|
2002-10-30
|
Microsoft Windows CONVERT.EXE FAT32 File Permission Conversion Failure
|
|
17122
Description:
(Description Provided by CVE) : A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."
|
2002-10-30
|
Microsoft IIS Permission Weakness .COM File Upload
|
|
59771
Description:
(Description Provided by CVE) : Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.
|
2002-10-30
|
Motorola SURFboard SB4200 SYN Port Scan Remote DoS
|
|
44634
Description:
Unknown / Incomplete
|
2002-10-29
|
Oracle Portal / Single Sign-on (SSO) Server Session Persistence
|
|
20827
Description:
Unknown / Incomplete
|
2002-10-29
|
Monkey HTTP Daemon User_main Overflow
|
|
20824
Description:
(Description Provided by CVE) : The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value.
|
2002-10-29
|
Monkey HTTP Daemon (monkeyd) Post_Method Function Crafted Content-Length Header DoS
|
|
59539
Description:
(Description Provided by CVE) : SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.
|
2002-10-29
|
SonicWALL Site IP Address URL Filtering Bypass
|
|
60235
Description:
(Description Provided by CVE) : NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic.
|
2002-10-29
|
NetDSL ADSL Modem 800 Cleartext Undocumented Credentials Remote Disclosure
|
|
60260
Description:
(Description Provided by CVE) : Multiple buffer overflows in (1) tetrinet_inmessage, (2) speclist_add and (3) config-getthemeinfo of GTetrinet 0.4.3 and earlier allow remote attackers to casue a denial of service and possibly execute arbitrary code.
|
2002-10-29
|
GTetrinet Multiple Functions Remote Overflow
|
|
14844
Description:
(Description Provided by CVE) : The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.
|
2002-10-28
|
Solaris WBEM SUNWwbdoc Package Permission Weakness
|
|
14845
Description:
(Description Provided by CVE) : The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.
|
2002-10-28
|
Solaris WBEM SUNWwbcou Package Permission Weakness
|
|
14846
Description:
(Description Provided by CVE) : The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.
|
2002-10-28
|
Solaris WBEM SUNWwbdev Package Permission Weakness
|
|
14847
Description:
(Description Provided by CVE) : The Web-Based Enterprise Management (WBEM) packages (1) SUNWwbdoc, (2) SUNWwbcou, (3) SUNWwbdev and (4) SUNWmgapp packages, when installed using Solaris 8 Update 1/01 or later, install files with world or group write permissions, which allows local users to gain root privileges or cause a denial of service.
|
2002-10-28
|
Solaris WBEM SUNWmgapp Package Permission Weakness
|
|
16018
Description:
(Description Provided by CVE) : compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in network.cgi.
|
2002-10-28
|
Mailreader with Sendmail compose.cgi Arbitrary Command Execution
|
|
59244
Description:
(Description Provided by CVE) : ** DISPUTED ** Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service (crash) via a port scan, possibly due to an ssh bug. NOTE: this issue could not be reproduced by the vendor.
|
2002-10-28
|
Cisco AS5350 w/ ACLs Port Scan Remote DoS
|
|
8192
Description:
(Description Provided by CVE) : Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot dot) sequences and a null byte (%00) in the configLanguage parameter.
|
2002-10-28
|
Mailreader nph-mr.cgi do Parameter Traversal Arbitrary File Access
|
|
59462
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page.
|
2002-10-28
|
AN HTTP Query String Error Page XSS
|
|
11954
Description:
(Description Provided by CVE) : Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.
|
2002-10-27
|
Microsoft Outlook Express .dbx Deleted E-mail Persistence
|
|
4284
Description:
phpBB contains a flaw that allows a remote attacker to gain administrative privileges. The issue is due to the admin_ug_auth.php script not validating form field input. If an attacker knows the fields required, they can post values that change an arbitrary account into an administrator account.
|
2002-10-27
|
phpBB admin_ug_auth.php Form Field Manipulation
|
|
12047
Description:
(Description Provided by CVE) : Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.
|
2002-10-27
|
MDaemon POP Server Multiple Command Remote Overflow DoS
|