Latest CVE Feed
-
4.6
MEDIUMCVE-2002-1513
The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges... Read more
Affected Products : tcp-ip_services- EPSS Score: %0.28
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0106
The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.... Read more
Affected Products : enterprise_firewall- EPSS Score: %0.75
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1524
Buffer overflow in XML parser in wsabi.dll of Winamp 3 (1.0.0.488) allows remote attackers to execute arbitrary code via a skin file (.wal) with a long include file tag.... Read more
Affected Products : winamp- EPSS Score: %11.48
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1499
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcom... Read more
Affected Products : factosystem_weblog- EPSS Score: %0.53
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1488
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian user is not in.... Read more
Affected Products : trillian- EPSS Score: %4.38
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1494
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.... Read more
Affected Products : html_os- EPSS Score: %0.52
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1497
Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response.... Read more
Affected Products : null_httpd- EPSS Score: %0.44
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1489
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.... Read more
Affected Products : planetweb- EPSS Score: %7.96
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1534
Macromedia Flash Player allows remote attackers to read arbitrary files via XML script in a .swf file that is hosted on a remote SMB share.... Read more
Affected Products : flash_player- EPSS Score: %0.57
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1551
Buffer overflow in nslookup in IBM AIX may allow attackers to cause a denial of service or execute arbitrary code.... Read more
Affected Products : aix- EPSS Score: %0.10
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1535
Secure Webserver 1.1 in Raptor 6.5 and Symantec Enterprise Firewall 6.5.2 allows remote attackers to identify IP addresses of hosts on the internal network via a CONNECT request, which generates different error messages if the host is present.... Read more
- EPSS Score: %0.82
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1545
CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.... Read more
Affected Products : personal_ftp_server- EPSS Score: %0.50
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1530
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.... Read more
Affected Products : superscout_email_filter- EPSS Score: %7.13
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1547
Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability th... Read more
Affected Products : netscreen_screenos- EPSS Score: %1.72
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2003-0080
The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.... Read more
- EPSS Score: %0.44
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1548
Unknown vulnerability in autofs on AIX 4.3.0, when using executable maps, allows attackers to execute arbitrary commands as root, possibly related to "string handling around how the executable map is called."... Read more
Affected Products : aix- EPSS Score: %0.06
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1541
BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash).... Read more
Affected Products : badblue- EPSS Score: %0.42
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2003-0127
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.... Read more
Affected Products : linux_kernel- EPSS Score: %0.95
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1557
Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.... Read more
Affected Products : optical_networking_systems_software- EPSS Score: %0.49
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0147
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of ... Read more
- EPSS Score: %21.35
- Published: Mar. 31, 2003
- Modified: Apr. 03, 2025