Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-2283 Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows XP
Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users.
1.9
2002-12-31 CVE-2002-2280 Configuration vulnerability in Openbsd
syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g.
local
low complexity
openbsd CWE-16
2.1
2002-12-31 CVE-2002-2275 Denial-Of-Service vulnerability in Fortres Grand Corporation Fortres 4.1
Fortres 101 4.1 allows local users to bypass Fortres by pressing the Windows and "F" key together for 30 seconds, which opens multiple windows and eventually causes explorer.exe to crash, which then opens an unrestricted explorer.exe.
local
low complexity
fortres-grand-corporation
2.1
2002-12-31 CVE-2002-2274 Unspecified vulnerability in Akfingerd 0.5
akfingerd 0.5 allows local users to read arbitrary files as the akfingerd user (nobody) via a symlink attack on the .plan file.
local
low complexity
akfingerd
2.1
2002-12-31 CVE-2002-2270 Permissions, Privileges, and Access Controls vulnerability in HP Hp-Ux 10.10/10.20/11.00
Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.
local
low complexity
hp CWE-264
3.6
2002-12-31 CVE-2002-2254 Permissions, Privileges, and Access Controls vulnerability in Linux Kernel
The experimental IP packet queuing feature in Netfilter / IPTables in Linux kernel 2.4 up to 2.4.19 and 2.5 up to 2.5.31, when a privileged process exits and network traffic is not being queued, may allow a later process with the same Process ID (PID) to access certain network traffic that would otherwise be restricted.
local
low complexity
linux CWE-264
2.1
2002-12-31 CVE-2002-2244 Race Condition vulnerability in Akfingerd 0.5
Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle.
local
low complexity
akfingerd CWE-362
2.1
2002-12-31 CVE-2002-2202 Local Security vulnerability in Microsoft Outlook Express 6.0
Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.
local
high complexity
microsoft
3.8
2002-12-31 CVE-2002-2177 Information Disclosure vulnerability in BEA Weblogic Server 6.1/7.0/7.0.0.1
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.
network
high complexity
bea
2.6
2002-12-31 CVE-2002-2172 Information Disclosure vulnerability in Shana Informed
Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information.
local
low complexity
shana
2.1