Latest CVE Feed
-
4.3
MEDIUMCVE-2002-1649
Cross-site scripting (XSS) vulnerability in read_body.php in SquirrelMail before 1.2.3 allows remote attackers to execute arbitrary Javascript via a javascript: URL in an IMG tag.... Read more
Affected Products : squirrelmail- EPSS Score: %0.76
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2002-2334
Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.... Read more
Affected Products : joe- EPSS Score: %0.14
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-2238
Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.... Read more
Affected Products : kunani_odbc_ftp_server- EPSS Score: %0.11
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1584
Unknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, allows remote attackers to gain privileges.... Read more
- EPSS Score: %5.26
- Published: Dec. 27, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1176
Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.... Read more
Affected Products : winamp- EPSS Score: %1.91
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1177
Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.... Read more
Affected Products : winamp- EPSS Score: %3.08
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1368
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Con... Read more
- EPSS Score: %26.75
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1369
jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
- EPSS Score: %9.97
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1385
openwebmail_init in Open WebMail 1.81 and earlier allows local users to execute arbitrary code via .. (dot dot) sequences in a login name, such as the name provided in the sessionid parameter for openwebmail-abook.pl, which is used to find a configuratio... Read more
Affected Products : open_webmail- EPSS Score: %0.05
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1327
Buffer overflow in the Windows Shell function in Microsoft Windows XP allows remote attackers to execute arbitrary code via an .MP3 or .WMA audio file with a corrupt custom attribute, aka "Unchecked Buffer in Windows Shell Could Enable System Compromise."... Read more
Affected Products : windows_xp- EPSS Score: %36.91
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1383
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as ... Read more
- EPSS Score: %16.21
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1367
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the... Read more
- EPSS Score: %3.90
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1372
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to... Read more
- EPSS Score: %8.92
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1371
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.... Read more
- EPSS Score: %5.87
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1363
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.... Read more
Affected Products : libpng- EPSS Score: %6.79
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2002-1366
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.... Read more
- EPSS Score: %0.09
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1351
Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) ... Read more
Affected Products : melange_chat_system- EPSS Score: %8.45
- Published: Dec. 24, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1381
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.... Read more
Affected Products : exim- EPSS Score: %3.05
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1345
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.... Read more
- EPSS Score: %2.13
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1361
overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter.... Read more
Affected Products : cobalt_raq_4- EPSS Score: %20.76
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025