Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2002-10-04 | CVE-2002-1097 | Unspecified vulnerability in Cisco products Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages. | 7.5 |
2002-10-04 | CVE-2002-1096 | Unspecified vulnerability in Cisco products Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code. | 7.5 |
2002-10-04 | CVE-2002-1092 | Authentication External Access vulnerability in Cisco Internal Group Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication. | 7.5 |
2002-10-04 | CVE-2002-1091 | Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width. | 7.5 |
2002-10-04 | CVE-2002-1090 | Unspecified vulnerability in Libesmtp Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses. | 7.5 |
2002-10-04 | CVE-2002-1088 | Buffer Overflow vulnerability in Novell Groupwise 6.0/6.0.1 Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command. | 7.5 |
2002-10-04 | CVE-2002-1086 | SQL-Injection vulnerability in ezContents Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities. | 7.5 |
2002-10-04 | CVE-2002-1085 | Cross-Site Scripting vulnerability in ezContents Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities. | 7.5 |
2002-10-04 | CVE-2002-1080 | Unspecified vulnerability in Aprelium Technologies Abyss web Server 1.0/1.0.3 The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl. | 7.5 |
2002-10-04 | CVE-2002-1076 | Buffer Overflow vulnerability in IPSwitch IMail Web Messaging HTTP Get Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0. | 7.5 |