Latest CVE Feed
-
5.0
MEDIUMCVE-2002-1170
The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.... Read more
- EPSS Score: %1.27
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2002-1147
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of servic... Read more
Affected Products : procurve_switch_4000m- EPSS Score: %5.93
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1178
Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.... Read more
Affected Products : jetty_http_server- EPSS Score: %10.45
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1154
anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web s... Read more
Affected Products : analog- EPSS Score: %0.67
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1189
The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.... Read more
Affected Products : unity_server- EPSS Score: %0.08
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1149
The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings.... Read more
Affected Products : invision_board- EPSS Score: %0.84
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1141
An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "D... Read more
Affected Products : services- EPSS Score: %18.09
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0865
A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet, ak... Read more
Affected Products : virtual_machine- EPSS Score: %13.13
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1152
Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing.... Read more
- EPSS Score: %0.91
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0843
Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.... Read more
- EPSS Score: %2.53
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0839
The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that woul... Read more
- EPSS Score: %0.14
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1138
Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overw... Read more
- EPSS Score: %11.40
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1148
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.... Read more
Affected Products : tomcat- EPSS Score: %36.69
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1175
The getmxrecord function in Fetchmail 6.0.0 and earlier does not properly check the boundary of a particular malformed DNS packet from a malicious DNS server, which allows remote attackers to cause a denial of service (crash) when Fetchmail attempts to re... Read more
- EPSS Score: %1.34
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1174
Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, whic... Read more
- EPSS Score: %4.28
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0969
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Ful... Read more
- EPSS Score: %0.10
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1137
Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a lon... Read more
- EPSS Score: %18.74
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1139
The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location... Read more
- EPSS Score: %20.17
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1153
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".... Read more
Affected Products : websphere_application_server- EPSS Score: %2.58
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1165
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or... Read more
- EPSS Score: %2.90
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025