search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2002-03-06 2002-02-06 2002-03-06 VU#977251 Oracle 9iAS XSQL Servlet ignores file permissions allowing arbitrary users to view sensitive configuration files
2002-03-06 2001-09-17 2002-03-06 VU#278971 Oracle 9i Application Server does not adequately handle requests for nonexistent JSP files thereby disclosing web folder path information
2002-03-04 2001-11-12 2002-04-16 VU#589523 Multiple implementations of the RADIUS protocol contain a digest calculation buffer overflow
2002-03-04 2001-11-29 2002-04-16 VU#936683 Multiple implementations of the RADIUS protocol do not adequately validate the vendor-length of the vendor-specific attributes
2002-03-04 2002-02-21 2002-03-06 VU#613459 Squid Proxy Server contains buffer overflow in parsing of the authentication portion of FTP URLs
2002-03-04 2002-02-27 2002-03-05 VU#310387 Cisco IOS discloses fragments of previous packets when Express Forwarding is enabled
2002-03-03 2002-03-02 2004-02-23 VU#165099 cryptcat does not encrypt data communications when -e command argument is used
2002-03-01 2002-02-27 2002-04-22 VU#234971 mod_ssl and Apache_SSL modules contain a buffer overflow in the implementation of the OpenSSL "i2d_SSL_SESSION" routine
2002-03-01 2002-02-25 2002-07-05 VU#230307 0 Linux kernel netfilter IRC DCC helper module creates overly permissive firewall rules
2002-03-01 2002-01-10 2002-03-15 VU#193523 Oracle9i Application Server allows unauthenticated access to PL/SQL applications via alternate Database Access Descriptor
2002-02-28 2002-02-06 2002-03-15 VU#750299 Oracle9i Application Server Apache PL/SQL module vulnerable to buffer overflow via HTTP request
2002-02-28 2002-02-06 2002-03-15 VU#659043 Oracle9i Application Server Apache PL/SQL module vulnerable to buffer overflow via Database Access Descriptor password
2002-02-28 2002-02-06 2002-03-15 VU#878603 Oracle9i Application Server Apache PL/SQL module vulnerable to buffer overflow via HTTP Authorization header
2002-02-28 2002-02-06 2002-03-15 VU#923395 Oracle9i Application Server Apache PL/SQL module vulnerable to buffer overflow via cache directory name
2002-02-27 2002-02-27 2002-02-27 VU#297363 PHP contains vulnerability in "php_mime_split" function allowing arbitrary code execution

Sponsored by CISA.