Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2002-10-04 CVE-2002-1097 Unspecified vulnerability in Cisco products
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.
network
low complexity
cisco
7.5
2002-10-04 CVE-2002-1096 Unspecified vulnerability in Cisco products
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code.
network
low complexity
cisco
7.5
2002-10-04 CVE-2002-1092 Authentication External Access vulnerability in Cisco Internal Group
Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.
network
low complexity
cisco
7.5
2002-10-04 CVE-2002-1091 Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
network
low complexity
mozilla netscape opera-software
7.5
2002-10-04 CVE-2002-1090 Unspecified vulnerability in Libesmtp
Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses.
network
low complexity
libesmtp
7.5
2002-10-04 CVE-2002-1088 Buffer Overflow vulnerability in Novell Groupwise 6.0/6.0.1
Buffer overflow in Novell GroupWise 6.0.1 Support Pack 1 allows remote attackers to execute arbitrary code via a long RCPT TO command.
network
low complexity
novell
7.5
2002-10-04 CVE-2002-1086 SQL-Injection vulnerability in ezContents
Multiple SQL injection vulnerabilities in ezContents 1.41 and earlier allow remote attackers to conduct unauthorized activities.
network
low complexity
visualshapers
7.5
2002-10-04 CVE-2002-1085 Cross-Site Scripting vulnerability in ezContents
Multiple cross-site scripting vulnerabilities in ezContents 1.41 and earlier allow remote attackers to execute script and steal cookies via the diary and other capabilities.
network
low complexity
visualshapers
7.5
2002-10-04 CVE-2002-1080 Unspecified vulnerability in Aprelium Technologies Abyss web Server 1.0/1.0.3
The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.
network
low complexity
aprelium-technologies
7.5
2002-10-04 CVE-2002-1076 Buffer Overflow vulnerability in IPSwitch IMail Web Messaging HTTP Get
Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.
network
low complexity
ipswitch
7.5