Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2002-07-23 | CVE-2002-0675 | Unspecified vulnerability in Pingtel Xpressa 1.2.5/1.2.7.4 Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone. | 4.6 |
2002-07-23 | CVE-2002-0673 | Cross-Site Request Forgery vulnerability in Xpressa 1.2.5/1.2.7.4 The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In to gain remote access and perform unauthorized actions. | 4.6 |
2002-07-23 | CVE-2002-0672 | Local Security vulnerability in Xpressa 1.2.5/1.2.7.4 Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null. | 4.6 |
2002-07-23 | CVE-2002-0643 | Unspecified vulnerability in Microsoft Data Engine and SQL Server The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System." | 4.6 |
2002-07-03 | CVE-2002-0621 | Buffer Overflow vulnerability in Microsoft Commerce Server 2000 Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer. | 5.0 |
2002-07-03 | CVE-2002-0620 | Buffer Overflow vulnerability in Microsoft Commerce Server 2000 Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API. | 5.0 |
2002-07-03 | CVE-2002-0566 | Denial of Service vulnerability in Oracle 9iAS Apache PL/SQL Module PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type. | 5.0 |
2002-07-03 | CVE-2002-0565 | Information Disclosure vulnerability in Oracle products Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages. | 5.0 |
2002-07-03 | CVE-2002-0563 | Improper Authentication vulnerability in Oracle products The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes. | 5.0 |
2002-07-03 | CVE-2002-0562 | Information Disclosure vulnerability in Oracle products The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa. | 5.0 |