Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2002-04-03 CVE-2002-0165 Local Security vulnerability in Logwatch 2.5
LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CVE-2002-0162.
local
low complexity
logwatch
7.2
2002-04-03 CVE-2002-0017 Buffer Overflow vulnerability in IRIX SNMP Daemon
Buffer overflow in SNMP daemon (snmpd) on SGI IRIX 6.5 through 6.5.15m allows remote attackers to execute arbitrary code via an SNMP request.
network
low complexity
sgi
7.5
2002-04-02 CVE-2002-0158 Heap Overflow vulnerability in Sun Solaris XSun Color Database File
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.
local
low complexity
sun
7.2
2002-04-01 CVE-2002-1639 Unspecified vulnerability in Oracle Configurator
Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host".
network
low complexity
oracle
7.5
2002-04-01 CVE-2001-1175 Unspecified vulnerability in Andries Brouwer Util-Linux 2.10S/2.11D
vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing.
local
low complexity
andries-brouwer
7.2
2002-04-01 CVE-2001-1174 Unspecified vulnerability in ELM Development Group ELM
Buffer overflow in Elm 2.5.5 and earlier allows remote attackers to execute arbitrary code via a long Message-ID header.
network
low complexity
elm-development-group
7.5
2002-04-01 CVE-2001-1171 Local Security vulnerability in Checkpoint Firewall-1 3.0B
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.
local
low complexity
checkpoint
7.2
2002-03-29 CVE-2002-0078 Unspecified vulnerability in Microsoft Internet Explorer 5.0.1/5.5/6.0
The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.
network
low complexity
microsoft
7.5
2002-03-26 CVE-2002-0163 Buffer Overflow vulnerability in Squid Compressed DNS
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via compressed DNS responses.
network
low complexity
squid
7.5
2002-03-25 CVE-2002-0145 Unspecified vulnerability in Scott Parish Chuid 1.0/1.1/1.2
chuid 1.2 and earlier does not properly verify the ownership of files that will be changed, which allows remote attackers to change files owned by other users, such as root.
network
low complexity
scott-parish
7.5