Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2002-05-31 CVE-2002-0296 Symbolic Link vulnerability in Tarantella Enterprise 3
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.
local
high complexity
tarantella
1.2
2002-05-31 CVE-2002-0294 Denial Of Service vulnerability in Alcatel-Lucent Omnipcx 4400
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.
local
low complexity
alcatel-lucent
2.1
2002-05-31 CVE-2002-0292 Cross-Site Scripting vulnerability in SlashCode
Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.
network
high complexity
open-source-development-network
2.6
2002-05-31 CVE-2002-0284 Remote Security vulnerability in Nullsoft Winamp 2.77/2.78
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.
network
high complexity
nullsoft
2.6
2002-05-29 CVE-2002-0377 Unspecified vulnerability in ROB Flynn Gaim 0.57
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.
local
low complexity
rob-flynn
2.1
2002-05-29 CVE-2002-0355 Unspecified vulnerability in SGI Irix
netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.
local
low complexity
sgi
2.1
2002-05-29 CVE-2002-0271 Unspecified vulnerability in ADA Core Technologies Gnat PRO Native 3.12P/3.13P/3.14P
Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.
local
high complexity
ada-core-technologies
1.2
2002-05-29 CVE-2002-0234 Unspecified vulnerability in Juniper Netscreen Screenos
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections.
local
low complexity
juniper
2.1
2002-05-16 CVE-2002-0214 Information Disclosure vulnerability in Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0/1.5.18.0
Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the WEP key from the registry key.
local
low complexity
intel
2.1
2002-05-16 CVE-2002-0213 xkas in Xinet K-AShare 0.011.01 for IRIX allows local users to read arbitrary files via a symlink attack on the VOLICON file, which is copied to the .HSicon file in a shared directory.
local
low complexity
xinet sgi
2.1