Show filters
330 Total Results
Displaying 321-330 of 330
Sort by:
Attacker Value
Unknown

CVE-2007-3022

Disclosure Date: June 05, 2007 (last updated October 04, 2023)
Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute force attacks.
0
Attacker Value
Unknown

CVE-2006-1966

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been disputed in followup posts that suggest that a protection feature is triggering a RST.
0
Attacker Value
Unknown

CVE-2005-3400

Disclosure Date: November 01, 2005 (last updated February 22, 2025)
Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."
0
Attacker Value
Unknown

CVE-2005-3221

Disclosure Date: October 14, 2005 (last updated February 22, 2025)
Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
0
Attacker Value
Unknown

CVE-2005-1837

Disclosure Date: June 01, 2005 (last updated February 22, 2025)
Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.
0
Attacker Value
Unknown

CVE-2004-2748

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message.
0
Attacker Value
Unknown

CVE-2002-0596

Disclosure Date: June 18, 2002 (last updated February 22, 2025)
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message.
0
Attacker Value
Unknown

CVE-2002-0595

Disclosure Date: June 18, 2002 (last updated February 22, 2025)
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory.
0
Attacker Value
Unknown

CVE-1999-1091

Disclosure Date: January 15, 2002 (last updated February 22, 2025)
UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.
0
Attacker Value
Unknown

CVE-2001-0693

Disclosure Date: September 20, 2001 (last updated February 22, 2025)
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
0