CVE-2003-0210
- EPSS 2.3%
- Published 12.05.2003 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.
- EPSS 0.4%
- Published 04.10.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.
CVE-2002-0938
- EPSS 3.11%
- Published 04.10.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the action argument in a link to setup.exe.
CVE-2002-0241
- EPSS 0.19%
- Published 29.05.2002 04:00:00
- Last modified 03.04.2025 01:03:51
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.
- EPSS 0.56%
- Published 22.04.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to read HTML, Java class, and image files outside the web root via a ..\.. (modified ..) i...
CVE-2002-0159
- EPSS 2.34%
- Published 22.04.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Format string vulnerability in the administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3.01 (build 40), allows remote attackers to crash the CSADMIN module only (denial of service of adm...
- EPSS 8.44%
- Published 11.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet.
CVE-2000-1056
- EPSS 0.52%
- Published 11.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.
- EPSS 1.52%
- Published 11.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.