Latest CVE Feed
-
10.0
HIGHCVE-2002-1974
The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.... Read more
Affected Products : zaurus- EPSS Score: %1.83
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1582
compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in netw... Read more
Affected Products : mailreader.com- EPSS Score: %1.48
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1572
Signed integer overflow in the bttv_read function in the bttv driver (bttv-driver.c) in Linux kernel before 2.4.20 has unknown impact and attack vectors.... Read more
Affected Products : linux_kernel- EPSS Score: %0.44
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1558
Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet.... Read more
Affected Products : optical_networking_systems_software- EPSS Score: %0.92
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1510
xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.... Read more
- EPSS Score: %0.81
- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1399
Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated u... Read more
Affected Products : postgresql- EPSS Score: %0.46
- Published: Jan. 17, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1359
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH prot... Read more
- EPSS Score: %87.00
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1257
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail.... Read more
Affected Products : windows_2000 windows_xp windows_95 windows_98 windows_nt windows_98se windows_me windows_2000_terminal_services- EPSS Score: %7.88
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1251
Buffer overflow in log2mail before 0.2.5.1 allows remote attackers to execute arbitrary code via a long log message.... Read more
Affected Products : log2mail- EPSS Score: %5.17
- Published: Nov. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1225
Multiple buffer overflows in Heimdal before 0.5, possibly in both the (1) kadmind and (2) kdc servers, may allow remote attackers to gain root access.... Read more
Affected Products : heimdal- EPSS Score: %1.48
- Published: Oct. 28, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0746
Vulnerability in template.dhcpo in AIX 4.3.3 related to an insecure linker argument.... Read more
Affected Products : aix- EPSS Score: %0.56
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0702
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS serve... Read more
- EPSS Score: %37.65
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0690
Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.... Read more
Affected Products : epolicy_orchestrator- EPSS Score: %17.82
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0369
Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode.... Read more
Affected Products : .net_framework- EPSS Score: %19.26
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0033
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.... Read more
- EPSS Score: %55.47
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0012
Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate ... Read more
Affected Products : snmp- EPSS Score: %54.25
- Published: Feb. 13, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1586
Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664.... Read more
Affected Products : simpleserver_www- EPSS Score: %2.62
- Published: Feb. 12, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2001-1583
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CV... Read more
Affected Products : sunos- EPSS Score: %59.82
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1370
prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitrary scripts via an HTTP request that modifies $_PHPLIB[libdir] to point to malicious code on another server, as seen in Horde 1.2.5 and ... Read more
Affected Products : phplib- EPSS Score: %30.07
- Published: Jul. 21, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1078
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6... Read more
Affected Products : extremail- EPSS Score: %4.22
- Published: Jun. 21, 2001
- Modified: Apr. 03, 2025