Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2002-05-29 CVE-2002-0250 Authentication Bypass vulnerability in HP AdvanceStack Switch
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change the switch's configuration and modify the administrator password.
network
low complexity
hp
7.5
2002-05-29 CVE-2002-0248 Unspecified vulnerability in Wliang Wmtv
wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.
local
low complexity
wliang
7.2
2002-05-29 CVE-2002-0247 Buffer Overflow vulnerability in WMTV
Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges.
local
low complexity
wliang
7.2
2002-05-29 CVE-2002-0246 Unspecified vulnerability in Caldera Unixware 7.1.1
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs such as vxprint.
local
low complexity
caldera
7.2
2002-05-29 CVE-2002-0245 Information Disclosure vulnerability in Lotus Domino Banner
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server's version name in the HTTP error message.
network
low complexity
lotus
7.5
2002-05-29 CVE-2002-0244 Unspecified vulnerability in Atheos 0.3.7
Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a ..
network
low complexity
atheos
7.5
2002-05-29 CVE-2002-0243 Unspecified vulnerability in Opera Software Opera web Browser
Cross-site scripting vulnerability in Opera 6.0 and earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed.
network
low complexity
opera-software
7.5
2002-05-29 CVE-2002-0242 Unspecified vulnerability in Microsoft Internet Explorer
Cross-site scripting vulnerability in Internet Explorer 6 earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed.
network
low complexity
microsoft
7.5
2002-05-29 CVE-2002-0241 Authentication vulnerability in Cisco Secure Access Control Server 3.0.1
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.
network
low complexity
cisco
7.5
2002-05-29 CVE-2002-0239 Local Buffer Overflow vulnerability in Hanterm 3.3/3.3.1
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.
local
low complexity
hanterm
7.2