Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2002-08-12 CVE-2002-0485 Improper Handling of Case Sensitivity vulnerability in Symantec Norton Antivirus
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.
network
low complexity
symantec CWE-178
7.5
2002-07-26 CVE-2002-0704 Improper Cross-boundary Removal of Sensitive Data vulnerability in Linux Kernel
The Network Address Translation (NAT) capability for Netfilter ("iptables") 1.2.6a and earlier leaks translated IP addresses in ICMP error messages.
network
low complexity
linux CWE-212
7.5
2002-07-11 CVE-2002-0653 Off-by-one Error vulnerability in Modssl MOD SSL
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entries.
local
low complexity
modssl CWE-193
7.8
2002-06-25 CVE-2002-0367 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
local
low complexity
microsoft
7.8
2002-06-18 CVE-2002-0401 NULL Pointer Dereference vulnerability in multiple products
SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.
network
low complexity
ethereal debian CWE-476
7.5
2002-05-16 CVE-2002-0184 Incorrect Calculation of Buffer Size vulnerability in multiple products
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.
local
low complexity
sudo-project debian CWE-131
7.8
2002-04-04 CVE-2002-0051 Improper Locking vulnerability in Microsoft Windows 2000
Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.
local
low complexity
microsoft CWE-667
7.8
2001-12-31 CVE-2001-1546 Inadequate Encryption Strength vulnerability in Mckesson Pathways Homecare 6.5
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file.
local
low complexity
mckesson CWE-326
7.8
2001-12-31 CVE-2001-1537 Cleartext Storage of Sensitive Information vulnerability in Symfony Twig
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies, which could allow attackers to obtain authentication information and gain privileges.
network
low complexity
symfony CWE-312
7.5
2001-12-31 CVE-2001-1536 Cleartext Storage of Sensitive Information vulnerability in Audiogalaxy
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain authentication information and gain unauthorized access via sniffing or a cross-site scripting attack.
network
low complexity
audiogalaxy CWE-312
7.5