Total
90 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2002-2119 | 1 Novell | 1 Edirectory | 2026-06-16 | 7.5 HIGH | 9.8 CRITICAL |
| Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing. | |||||
| CVE-2002-1820 | 1 Ultimate Php Board Project | 1 Ultimate Php Board | 2026-06-16 | 7.5 HIGH | 9.8 CRITICAL |
| register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a." | |||||
| CVE-2002-0485 | 1 Symantec | 1 Norton Antivirus | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients. | |||||
| CVE-2001-1238 | 1 Microsoft | 1 Windows 2000 | 2026-06-16 | 4.6 MEDIUM | 7.8 HIGH |
| Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager. | |||||
| CVE-2001-0795 | 1 Cmfperception | 1 Liteserve | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names. | |||||
| CVE-2001-0766 | 2 Apache, Apple | 2 Http Server, Mac Os X | 2026-06-16 | 7.5 HIGH | 9.8 CRITICAL |
| Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters. | |||||
| CVE-2000-0499 | 1 Bea | 1 Weblogic Server | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. | |||||
| CVE-2000-0498 | 1 Unify | 1 Ewave Servletexec | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. | |||||
| CVE-2000-0497 | 1 Ibm | 1 Websphere Application Server | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. | |||||
| CVE-1999-0239 | 1 Netscape | 1 Fasttrack Server | 2026-06-16 | 5.0 MEDIUM | 7.5 HIGH |
| Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET. | |||||
