Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2002-1483

    db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).... Read more

    Affected Products : db4web
    • EPSS Score: %5.11
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1477

    graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.... Read more

    Affected Products : cacti
    • EPSS Score: %2.65
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2002-1464

    Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.... Read more

    Affected Products : b2
    • EPSS Score: %1.21
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2002-1480

    Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script into guestbook pages, which is executed when the administrator deletes the entry.... Read more

    Affected Products : phpgb
    • EPSS Score: %0.88
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1469

    scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environmen... Read more

    Affected Products : scponly
    • EPSS Score: %7.53
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-1479

    Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.... Read more

    Affected Products : cacti
    • EPSS Score: %0.05
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-1476

    Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 element... Read more

    Affected Products : netbsd
    • EPSS Score: %0.10
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1475

    Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service.... Read more

    Affected Products : tru64
    • EPSS Score: %0.71
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1467

    Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).... Read more

    Affected Products : flash_player shockwave
    • EPSS Score: %0.49
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2002-1484

    DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a... Read more

    Affected Products : db4web
    • EPSS Score: %7.03
    • Published: Apr. 22, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-1054

    mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.... Read more

    Affected Products : mod_access_referer
    • EPSS Score: %7.09
    • Published: Apr. 16, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0203

    Buffer overflow in moxftp 2.2 and earlier allows remote malicious FTP servers to execute arbitrary code via a long FTP banner.... Read more

    Affected Products : moxftp xftp
    • EPSS Score: %11.21
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1436

    The web handler for Perl 5.003 on Novell NetWare 5.1 and NetWare 6 allows remote attackers to execute arbitrary Perl code via an HTTP POST request.... Read more

    Affected Products : netware netware
    • EPSS Score: %9.67
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1413

    RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.... Read more

    Affected Products : netware netware
    • EPSS Score: %1.69
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1423

    tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter.... Read more

    Affected Products : fudforum
    • EPSS Score: %9.65
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1411

    Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.... Read more

    Affected Products : photo_gallery_system
    • EPSS Score: %0.27
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1443

    The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler.... Read more

    Affected Products : toolbar
    • EPSS Score: %0.38
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0135

    vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.... Read more

    Affected Products : linux
    • EPSS Score: %0.53
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1407

    TinySSL 1.02 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.... Read more

    Affected Products : tinyssl
    • EPSS Score: %0.48
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1431

    Belkin F5D5230-4 4-Port Cable/DSL Gateway Router 1.20.000 modifies the source IP address of internal packets to that of the router's external interface when forwarding a request from an internal host to an internal web server, which allows remote attacker... Read more

    • EPSS Score: %0.74
    • Published: Apr. 11, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 291170 Results