Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2003-0001

    Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.... Read more

    • EPSS Score: %3.61
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2003-0012

    The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.... Read more

    Affected Products : bugzilla
    • EPSS Score: %0.06
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1394

    Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.... Read more

    Affected Products : tomcat
    • EPSS Score: %5.35
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-1402

    Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.... Read more

    Affected Products : postgresql
    • EPSS Score: %0.14
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-1395

    Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via imm... Read more

    Affected Products : internet_message
    • EPSS Score: %0.08
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2003-0032

    Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to dynamically load algorithms via libtool.... Read more

    Affected Products : libmcrypt
    • EPSS Score: %0.79
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1393

    Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.... Read more

    Affected Products : linux kde
    • EPSS Score: %2.44
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0013

    The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote at... Read more

    Affected Products : bugzilla
    • EPSS Score: %1.11
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 6.5

    MEDIUM
    CVE-2002-1401

    Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an ... Read more

    Affected Products : postgresql
    • EPSS Score: %1.03
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2003-0026

    Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE capability for ISC DHCPD 3.0 through 3.0.1RC10, allow remote attackers to execute arbitrary code via a DHCP message containing a long host... Read more

    Affected Products : dhcpd
    • EPSS Score: %12.42
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-1392

    faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to modify fax transmission privileges.... Read more

    Affected Products : mgetty
    • EPSS Score: %0.08
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-1403

    dhcpcd DHCP client daemon 1.3.22 and earlier allows local users to execute arbitrary code via shell metacharacters that are fed from a dhcpd .info script into a .exe script.... Read more

    Affected Products : linux dhcpcd
    • EPSS Score: %0.06
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1390

    The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbitrary files via a crafted URL.... Read more

    Affected Products : geneweb
    • EPSS Score: %0.36
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1399

    Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated u... Read more

    Affected Products : postgresql
    • EPSS Score: %0.46
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-1398

    Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input."... Read more

    Affected Products : postgresql
    • EPSS Score: %0.16
    • Published: Jan. 17, 2003
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2003-0014

    gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more

    Affected Products : bmv
    • EPSS Score: %0.08
    • Published: Jan. 11, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0629

    The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via multiple connections to the server.... Read more

    • EPSS Score: %1.32
    • Published: Jan. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0627

    The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requests.... Read more

    • EPSS Score: %0.79
    • Published: Jan. 07, 2003
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0630

    The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via long or malformed ICMP packets.... Read more

    • EPSS Score: %1.32
    • Published: Jan. 07, 2003
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0628

    The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack.... Read more

    • EPSS Score: %1.42
    • Published: Jan. 07, 2003
    • Modified: Apr. 03, 2025
Showing 20 of 291193 Results