Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2002-02-27 CVE-2002-0003 Buffer Overflow vulnerability in Groff Pre-Processor
Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system.
network
low complexity
gnu
7.5
2002-02-27 CVE-2002-0001 Buffer Overflow vulnerability in Mutt Address Handling
Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commands via an improperly terminated comment or phrase in the address list.
network
low complexity
mutt
7.5
2002-02-13 CVE-2001-1058 Unspecified vulnerability in Wolfram Research Mathematica 4.0/4.1
The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to bypass access control (specified by the -restrict argument) and steal a license via a client request that includes the name of a host that is allowed to obtain the license.
network
low complexity
wolfram-research
7.5
2002-02-06 CVE-2001-1371 Permissions, Privileges, and Access Controls vulnerability in Oracle Application Server 1.0.2
The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.
network
low complexity
oracle CWE-264
7.5
2002-01-31 CVE-2002-0045 slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs.
network
low complexity
openldap redhat
7.5
2002-01-31 CVE-2002-0043 Unspecified vulnerability in Todd Miller Sudo
sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.
local
low complexity
todd-miller
7.2
2002-01-31 CVE-2002-0010 Unspecified vulnerability in Mozilla Bugzilla
Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges.
network
low complexity
mozilla
7.5
2002-01-31 CVE-2002-0008 Unspecified vulnerability in Mozilla Bugzilla
Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.
network
low complexity
mozilla
7.5
2002-01-31 CVE-2002-0002 Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
network
low complexity
stunnel engardelinux mandrakesoft redhat
7.5
2002-01-31 CVE-2001-0891 Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.
local
low complexity
sgi cray
7.2