CVE-2002-0294
https://notcve.org/view.php?id=CVE-2002-0294
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system. Alcatel 4400 instala el comando /chetc/shutdown con privilegios setgid, lo que permite a muchos usuarios locales apagar el sistema. • http://marc.info/?l=bugtraq&m=101413767925869&w=2 http://www.securityfocus.com/bid/4130 •
CVE-2002-0236 – Lucent 8.x - VitalNet Password Authentication Bypass
https://notcve.org/view.php?id=CVE-2002-0236
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user. Lucent VitalSuite 8.0 hasta 8.2, incluyendo VitalNet, VitalEvent, y VitalHelp/VitalAnalysis, permite a atacantes remotos que se salten la autentificación por medio de una petición HTTP directa al programa VsSetCookie.exe, el cual retorna una cookie válida para el usuario deseado. • https://www.exploit-db.com/exploits/21203 http://marc.info/?l=bugtraq&m=101294507827698&w=2 http://www.iss.net/security_center/static/7936.php http://www.securityfocus.com/bid/3784 •
CVE-2002-0295
https://notcve.org/view.php?id=CVE-2002-0295
Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges. Alcatel OmniPCX 4400 instala ficheros con permisos de escritura para todos los usuarios, lo que permite a usuarios locales reconfigurar el sistema y posiblemente ganar privilegios. • http://marc.info/?l=bugtraq&m=101413767925869&w=2 http://www.securityfocus.com/bid/4133 •
CVE-2002-0293
https://notcve.org/view.php?id=CVE-2002-0293
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file. El servicio FTP en Alcatel OmniPCX 4400 permite al usuario "halt" ganar privilegios de root modificando el fichero de root .profile. • http://marc.info/?l=bugtraq&m=101413767925869&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/8225 •
CVE-2001-1377
https://notcve.org/view.php?id=CVE-2001-1377
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2. • ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:02.asc http://archives.neohapsis.com/archives/linux/suse/2002-q2/0362.html http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000466 http://marc.info/?l=bugtraq&m=101537153021792&w=2 http://www.cert.org/advisories/CA-2002-06.html http://www.iss.net/security_center/static/8354.php http://www.kb.cert.org/vuls/id/936683 http://www.redhat.com/support/errata/RHSA-2002-030.html http://www •