Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2004-0084

    Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a differ... Read more

    Affected Products : openbsd x11r6
    • EPSS Score: %14.63
    • Published: Mar. 03, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-1009

    Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote at... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %1.08
    • Published: Mar. 29, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0509

    SQL injection vulnerability in Cyberstrong eShop 4.2 and earlier allows remote attackers to steal authentication information and gain privileges via the ProductCode parameter in (1) 10expand.asp, (2) 10browse.asp, and (3) 20review.asp.... Read more

    Affected Products : eshop
    • EPSS Score: %5.79
    • Published: Aug. 07, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0255

    The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does no... Read more

    Affected Products : privacy_guard
    • EPSS Score: %5.43
    • Published: May. 27, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0248

    The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.... Read more

    Affected Products : linux
    • EPSS Score: %1.44
    • Published: Jun. 16, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-0098

    Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.... Read more

    Affected Products : debian_linux apcupsd
    • EPSS Score: %6.82
    • Published: Mar. 03, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-0892

    Buffer overflow in smail 3.2.0.120 allows remote attackers or local users to execute arbitrary code via a long string in the MAIL FROM command and possibly other SMTP commands.... Read more

    Affected Products : smail
    • EPSS Score: %3.99
    • Published: Mar. 28, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1361

    overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.... Read more

    Affected Products : cobalt_raq_4
    • EPSS Score: %20.76
    • Published: Dec. 23, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1226

    Unknown vulnerabilities in Heimdal before 0.5 with unknown impact, possibly in the (1) kadmind and (2) kdc servers, may allow remote or local attackers to gain root or other access, but not via buffer overflows (CVE-2002-1225).... Read more

    Affected Products : heimdal
    • EPSS Score: %0.42
    • Published: Oct. 28, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1215

    Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 694 (incorrectly claimed as TCP in some sources).... Read more

    Affected Products : heartbeat
    • EPSS Score: %15.35
    • Published: Oct. 28, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0797

    Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %5.28
    • Published: Aug. 12, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0513

    The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.... Read more

    Affected Products : popper_mod
    • EPSS Score: %0.89
    • Published: Aug. 12, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1009

    Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.... Read more

    Affected Products : fetchmail
    • EPSS Score: %13.12
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0960

    Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.... Read more

    • EPSS Score: %1.16
    • Published: Sep. 15, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1196

    Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.... Read more

    Affected Products : webmin
    • EPSS Score: %3.92
    • Published: Dec. 17, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0248

    Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.... Read more

    Affected Products : hp-ux irix
    • EPSS Score: %5.32
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0022

    simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.... Read more

    Affected Products : simplestguest.cgi
    • EPSS Score: %3.71
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0963

    Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc... Read more

    Affected Products : word windows_2000
    • EPSS Score: %44.14
    • Published: Feb. 09, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2000-1042

    Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.... Read more

    Affected Products : mandrake_linux
    • EPSS Score: %0.50
    • Published: Dec. 11, 2000
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2000-0961

    Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.... Read more

    • EPSS Score: %0.84
    • Published: Dec. 19, 2000
    • Modified: Apr. 03, 2025
Showing 20 of 291058 Results