Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2002-07-23 CVE-2002-0675 Unspecified vulnerability in Pingtel Xpressa 1.2.5/1.2.7.4
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone.
local
low complexity
pingtel
4.6
2002-07-23 CVE-2002-0673 Cross-Site Request Forgery vulnerability in Xpressa 1.2.5/1.2.7.4
The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In to gain remote access and perform unauthorized actions.
local
low complexity
pingtel
4.6
2002-07-23 CVE-2002-0672 Local Security vulnerability in Xpressa 1.2.5/1.2.7.4
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null.
local
low complexity
pingtel
4.6
2002-07-23 CVE-2002-0643 Unspecified vulnerability in Microsoft Data Engine and SQL Server
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
local
low complexity
microsoft
4.6
2002-07-03 CVE-2002-0621 Buffer Overflow vulnerability in Microsoft Commerce Server 2000
Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.
network
low complexity
microsoft
5.0
2002-07-03 CVE-2002-0620 Buffer Overflow vulnerability in Microsoft Commerce Server 2000
Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
network
low complexity
microsoft
5.0
2002-07-03 CVE-2002-0566 Denial of Service vulnerability in Oracle 9iAS Apache PL/SQL Module
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.
network
low complexity
oracle
5.0
2002-07-03 CVE-2002-0565 Information Disclosure vulnerability in Oracle products
Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.
network
low complexity
oracle
5.0
2002-07-03 CVE-2002-0563 Improper Authentication vulnerability in Oracle products
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.
network
low complexity
oracle CWE-287
5.0
2002-07-03 CVE-2002-0562 Information Disclosure vulnerability in Oracle products
The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa.
network
low complexity
oracle
5.0