Latest CVE Feed
-
7.5
HIGHCVE-2002-1481
savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a denial of service or execute arbitrary PHP code by using savesettings.php to modify config.php.... Read more
Affected Products : phpgb- EPSS Score: %6.76
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1466
CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.... Read more
Affected Products : b2- EPSS Score: %1.18
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1482
SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote attackers to gain administrative privileges via SQL code in the password entry.... Read more
Affected Products : phpgb- EPSS Score: %0.69
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1474
Unknown vulnerability or vulnerabilities in TCP/IP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to cause a denial of service.... Read more
Affected Products : tru64- EPSS Score: %0.71
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1467
Macromedia Flash Plugin before 6,0,47,0 allows remote attackers to bypass the same-domain restriction and read arbitrary files via (1) an HTTP redirect, (2) a "file://" base in a web document, or (3) a relative URL from a web archive (mht file).... Read more
- EPSS Score: %0.49
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2002-1484
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a... Read more
Affected Products : db4web- EPSS Score: %7.03
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1477
graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.... Read more
Affected Products : cacti- EPSS Score: %2.65
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1475
Unknown vulnerability in the ARP component for HP Tru64 UNIX 4.0f, 4.0g, and 5.0a allows remote attackers to "take over packets destined for another host" and cause a denial of service.... Read more
Affected Products : tru64- EPSS Score: %0.71
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1476
Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 element... Read more
Affected Products : netbsd- EPSS Score: %0.10
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1479
Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.... Read more
Affected Products : cacti- EPSS Score: %0.05
- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-1054
mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.... Read more
Affected Products : mod_access_referer- EPSS Score: %7.09
- Published: Apr. 16, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1418
Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (ABEND) via a long module name.... Read more
- EPSS Score: %3.92
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0169
hpnst.exe in the GoAhead-Webs webserver for HP Instant TopTools before 5.55 allows remote attackers to cause a denial of service (CPU consumption) via a request to hpnst.exe that calls itself, which causes an infinite loop.... Read more
Affected Products : instant_toptools- EPSS Score: %14.56
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1432
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.... Read more
Affected Products : a-cart metacart midicart_asp midicart_asp_maxi midicart_asp_plus salescart-pro salescart-std- EPSS Score: %7.52
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2003-0132
A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.... Read more
Affected Products : http_server- EPSS Score: %80.96
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1416
The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.... Read more
Affected Products : webeasymail- EPSS Score: %0.62
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1409
ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state."... Read more
Affected Products : hp-ux- EPSS Score: %0.10
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0690
Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET request with a URI containing format strings.... Read more
Affected Products : epolicy_orchestrator- EPSS Score: %17.82
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1413
RCONAG6 for Novell Netware SP2, while running RconJ in secure mode, allows remote attackers to bypass authentication using the RconJ "Secure IP" (SSL) option during a connection.... Read more
- EPSS Score: %1.69
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1406
Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior."... Read more
Affected Products : hp-ux- EPSS Score: %0.06
- Published: Apr. 11, 2003
- Modified: Apr. 03, 2025