
CVE-2002-0391
https://notcve.org/view.php?id=CVE-2002-0391
12 Aug 2002 — Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd. • ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-055.0.txt • CWE-190: Integer Overflow or Wraparound •

CVE-2002-0366
https://notcve.org/view.php?id=CVE-2002-0366
03 Jul 2002 — Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. • http://online.securityfocus.com/archive/1/276776 •

CVE-2002-0367 – Microsoft Windows Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2002-0367
25 Jun 2002 — smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit. smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. • https://www.exploit-db.com/exploits/21344 • CWE-269: Improper Privilege Management •

CVE-2002-0421
https://notcve.org/view.php?id=CVE-2002-0421
11 Jun 2002 — IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr. IIS 4.0 permite a usuarios locales eludir la restricción de "Los usuarios no pueden cambiar la contraseña" (User cannot change password) para Windows NT invocando directamente los programas de cambio de conrtaseña .htr del directorio /iisadmpwd, incluyendo: aexp2... • http://online.securityfocus.com/archive/1/259963 •

CVE-2002-0151
https://notcve.org/view.php?id=CVE-2002-0151
04 Apr 2002 — Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request. Desbordamiento de buffer en el proveedor múltiple de UNC (MUP) en sistemas operativos Microsoft Windows permite a usuarios locales provocar una denegación de servicio y posiblemente ganar privilegios de SYSTEM mediante una petición UNC larga. • http://marc.info/?l=bugtraq&m=101793727306282&w=2 •

CVE-2002-0070
https://notcve.org/view.php?id=CVE-2002-0070
15 Mar 2002 — Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled. El desbordamiento del búfer en el Windows Shell (usado como escritorio de Windows) permite a atacantes locales y posibles atacantes remotos, la ejecución de código arbitrario mediante un manejador de URL que no ha sido eliminado de una aplicación defectuosamente desinstal... • http://marc.info/?l=bugtraq&m=101594127017290&w=2 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2002-0018
https://notcve.org/view.php?id=CVE-2002-0018
08 Mar 2002 — In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain. En Windows NT y Windows 2000, un dominio valido que recibe información de autorización de un dominio de confi... • http://www.securityfocus.com/bid/3997 •

CVE-2002-0053
https://notcve.org/view.php?id=CVE-2002-0053
18 Feb 2002 — Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available. Desbordamiento de buffer en el agente del servicio SNMP en Windows 95/98/98SE... • http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0012 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2001-0879
https://notcve.org/view.php?id=CVE-2001-0879
20 Dec 2001 — Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service. Vulnerabilidad de cadena formateada en las funciones de ejecución C en SQL Server 7.0 y 2000 permite a atacantes remotos provocar una denegación de servicio. • http://marc.info/?l=bugtraq&m=100891252317406&w=2 •

CVE-2001-0663 – Microsoft Windows NT/2000 - Terminal Server Service RDP Denial of Service
https://notcve.org/view.php?id=CVE-2001-0663
06 Dec 2001 — Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets. • https://www.exploit-db.com/exploits/21123 •