Latest CVE Feed
-
10.0
HIGHCVE-2002-0599
Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen.... Read more
Affected Products : blahz-dns- EPSS Score: %4.75
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0746
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.... Read more
Affected Products : aix- EPSS Score: %0.56
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1189
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character... Read more
Affected Products : internet_explorer- EPSS Score: %54.02
- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0525
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.... Read more
Affected Products : inn- EPSS Score: %4.36
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0508
wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.... Read more
Affected Products : wwwisis- EPSS Score: %4.43
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0449
Buffer overflow in webpsvc.exe for Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long argument to webplus.exe program, which triggers the overflow in webpsvc.exe.... Read more
Affected Products : web\+_server- EPSS Score: %13.01
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0437
Smsd in SMS Server Tools (SMStools) before 1.4.8 allows remote attackers to execute arbitrary commands via shell metacharacters (backquotes) in message text, as described with the term "string format vulnerability" by some sources.... Read more
Affected Products : sms_server_tools- EPSS Score: %2.19
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0480
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have conn... Read more
Affected Products : realsecure_nokia- EPSS Score: %0.99
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0265
Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and 10.2.0.1 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB17 in the Oracle Text component and (2) DB18 in the Program In... Read more
Affected Products : database_server- EPSS Score: %2.81
- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0395
The TFTP server for Red-M 1050 (Bluetooth Access Point) can not be disabled and makes it easier for remote attackers to crack the administration password via brute force methods.... Read more
Affected Products : 1050ap_lan_acess_point- EPSS Score: %1.21
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0369
Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode.... Read more
Affected Products : .net_framework- EPSS Score: %19.26
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4865
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname.... Read more
Affected Products : db2_universal_database- EPSS Score: %28.78
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0394
Red-M 1050 (Bluetooth Access Point) uses case insensitive passwords, which makes it easier for attackers to conduct a brute force guessing attack due to the smaller space of possible passwords.... Read more
Affected Products : 1050ap_lan_acess_point- EPSS Score: %0.70
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2007-6330
Meridian Prolog Manager 2007, and 7.5 and earlier, sends all usernames and passwords to the client in a (1) cleartext or (2) weakly encrypted format to support client-side login authentication, which makes it easier for remote attackers to obtain database... Read more
Affected Products : prolog_manager- EPSS Score: %5.10
- Published: Dec. 13, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2002-0287
pforum 1.14 and earlier does not explicitly enable PHP magic quotes, which allows remote attackers to bypass authentication and gain administrator privileges via an SQL injection attack when the PHP server is not configured to use magic quotes by default.... Read more
Affected Products : pforum- EPSS Score: %0.69
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0311
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.... Read more
- EPSS Score: %3.74
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3653
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length f... Read more
Affected Products : brightstor_arcserve_backup brightstor_arcserve_backup brightstor_arcserve_backup_laptops_desktops brightstor_portal brightstor_process_automation_manager brightstor_san_manager brightstor_storage_resource_manager etrust_admin etrust_audit_aries etrust_audit_irecorder +24 more products- EPSS Score: %30.44
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3595
By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.... Read more
Affected Products : windows_xp- EPSS Score: %36.98
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3587
Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.... Read more
Affected Products : clamav- EPSS Score: %0.37
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3453
Multiple unspecified vulnerabilities in Web Cache in Oracle Application Server 1.0 up to 10.1.2.0 has unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS12 and (2) AS14.... Read more
Affected Products : application_server- EPSS Score: %1.54
- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025