Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-1869 Improper Locking vulnerability in Heysoft Eventsave and Eventsave+
Heysoft EventSave 5.1 and 5.2 and Heysoft EventSave+ 5.1 and 5.2 does not check whether the log file can be written to, which allows attackers to prevent events from being recorded by opening the log file using an application such as Microsoft's Event Viewer.
local
low complexity
heysoft CWE-667
3.3
2002-12-31 CVE-2002-1848 Unspecified vulnerability in Tightvnc
TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords.
local
low complexity
tightvnc
2.1
2002-12-31 CVE-2002-1827 Denial Of Service vulnerability in Sendmail File Locking
Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files.
local
low complexity
sendmail
2.1
2002-12-31 CVE-2002-1813 Local File Execution vulnerability in AOL Instant Messenger
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link.
network
high complexity
aol
2.6
2002-12-31 CVE-2002-1791 Unspecified vulnerability in SGI Irix
SGI IRIX 6.5 through 6.5.17 creates temporary desktop files with world-writable permissions, which allows local users to overwrite or corrupt those files.
local
low complexity
sgi
2.1
2002-12-31 CVE-2002-1786 Unspecified vulnerability in SGI Irix
SGI IRIX 6.5 through 6.5.14 applies a umask of 022 to root core dumps, which allows local users to read the core dumps and possibly obtain sensitive information.
local
low complexity
sgi
2.1
2002-12-31 CVE-2002-1785 Cross-Site Scripting vulnerability in Zeus Web Server Admin Interface
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi.
1.9
2002-12-31 CVE-2002-1782 Unspecified vulnerability in University of Washington Uw-Imap 2001.0A
The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP account to read arbitrary files as that user.
local
low complexity
university-of-washington
2.1
2002-12-31 CVE-2002-1764 Unspecified vulnerability in Adobe Acrobat Reader 4.0.5
acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
low complexity
adobe
2.1
2002-12-31 CVE-2002-1754 Denial-Of-Service vulnerability in Netware Client
Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.
local
low complexity
novell
2.1