search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2002-03-06 2002-02-06 2002-03-06 VU#977251 Oracle 9iAS XSQL Servlet ignores file permissions allowing arbitrary users to view sensitive configuration files
2002-03-04 2002-02-21 2002-03-06 VU#613459 Squid Proxy Server contains buffer overflow in parsing of the authentication portion of FTP URLs
2002-03-06 2001-09-17 2002-03-06 VU#278971 Oracle 9i Application Server does not adequately handle requests for nonexistent JSP files thereby disclosing web folder path information
2002-03-06 2002-02-06 2002-03-06 VU#798611 Oracle 9iAS contains cross-site scripting vulnerability in "htp.print"
2002-03-06 2002-02-06 2002-03-06 VU#476619 Oracle 9iAS default configuration allows arbitrary users to view sensitive configuration files
2002-03-04 2002-02-27 2002-03-05 VU#310387 Cisco IOS discloses fragments of previous packets when Express Forwarding is enabled
2001-01-18 2001-01-18 2002-03-05 VU#118892 Older SSH clients do not allow users to disable X11 forwarding
2001-05-01 2001-02-28 2002-03-05 VU#848944 Cisco IOS creates SNMP read-only community string
2001-05-01 2001-02-28 2002-03-05 VU#645400 Cisco IOS/CatOS exposes read-write SNMP community string via traversal of View-based Access Control MIB (VACM) using read-only community string
2001-05-01 2001-02-27 2002-03-05 VU#976280 Multiple networking devices allow SNMP objects to be viewed/modified via ILMI community string
2002-02-27 2002-01-10 2002-03-05 VU#936507 Oracle 9iAS allows access to CGI script source code within CGI-BIN directory
2001-05-01 2001-02-28 2002-03-05 VU#840665 Cisco IOS/X12-X15 has default SNMP read/write string of "cable-docsis"
2000-12-22 2000-11-20 2002-03-05 VU#671444 Input validation error in quikstore.cgi allows attackers to execute commands
2000-10-06 2000-07-20 2002-03-05 VU#38950 MS Outlook "Cache Bypass" allows attackers to circumvent Internet Zone security policy
2001-01-18 2001-01-18 2002-03-05 VU#315308 Weak CRC allows last block of IDEA-encrypted SSH packet to be changed without notice

Sponsored by CISA.