Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2002-1170

    The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.... Read more

    Affected Products : net-snmp linux
    • EPSS Score: %1.27
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-1150

    The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL... Read more

    Affected Products : netmeeting
    • EPSS Score: %0.93
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1153

    IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".... Read more

    Affected Products : websphere_application_server
    • EPSS Score: %2.58
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0863

    Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Wea... Read more

    • EPSS Score: %9.51
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1139

    The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location... Read more

    • EPSS Score: %20.17
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2002-0969

    Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Ful... Read more

    Affected Products : mysql windows
    • EPSS Score: %0.10
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-1165

    Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or... Read more

    Affected Products : netbsd sendmail
    • EPSS Score: %2.90
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1137

    Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a lon... Read more

    Affected Products : sql_server data_engine
    • EPSS Score: %18.74
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1138

    Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overw... Read more

    Affected Products : sql_server sql_server data_engine
    • EPSS Score: %11.40
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1156

    Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled.... Read more

    Affected Products : http_server
    • EPSS Score: %23.89
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0839

    The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that woul... Read more

    Affected Products : debian_linux http_server
    • EPSS Score: %0.14
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1141

    An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "D... Read more

    Affected Products : services
    • EPSS Score: %18.09
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1149

    The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings.... Read more

    Affected Products : invision_board
    • EPSS Score: %0.84
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-1189

    The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.... Read more

    Affected Products : unity_server
    • EPSS Score: %0.08
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1154

    anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web s... Read more

    Affected Products : analog
    • EPSS Score: %0.67
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0867

    Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw."... Read more

    Affected Products : virtual_machine
    • EPSS Score: %11.53
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1178

    Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execute arbitrary commands via ..\ (dot-dot backslash) sequences in an HTTP request to the cgi-bin directory.... Read more

    Affected Products : jetty_http_server
    • EPSS Score: %10.45
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0864

    The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of S... Read more

    • EPSS Score: %18.45
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2002-0840

    Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page vis... Read more

    • EPSS Score: %88.77
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1174

    Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) long headers that are not properly processed by the readheaders function, or (2) via long Received: headers, whic... Read more

    Affected Products : linux fetchmail
    • EPSS Score: %4.28
    • Published: Oct. 11, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291741 Results