Latest CVE Feed
-
5.0
MEDIUMCVE-2002-1283
Buffer overflow in Novell iManager (eMFrame) before 1.5 allows remote attackers to cause a denial of service via an authentication request with a long Distinguished Name (DN) attribute.... Read more
Affected Products : emframe- EPSS Score: %0.37
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1291
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL.... Read more
Affected Products : java_virtual_machine- EPSS Score: %6.39
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1306
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute arbitrary code via the "lisa" daemon, and (2) remote attackers to execute arbitrary code via a certain "lan:... Read more
- EPSS Score: %4.81
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1282
Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL.... Read more
- EPSS Score: %5.50
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1294
The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other una... Read more
Affected Products : java_virtual_machine- EPSS Score: %5.59
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1309
Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia ColdFusion 6.0 allows remote attackers to execute arbitrary via an HTTP GET request with a long .cfm file name.... Read more
Affected Products : coldfusion- EPSS Score: %4.02
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1289
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instanc... Read more
Affected Products : java_virtual_machine- EPSS Score: %6.46
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1284
The wizard in KGPG 0.6 through 0.8.2 does not properly provide the passphrase to gpg when creating new keys, which causes secret keys to be created with an empty passphrase and allows local attackers to steal the keys if they can be read.... Read more
Affected Products : kgpg- EPSS Score: %0.07
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1307
Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name.... Read more
Affected Products : mhonarc- EPSS Score: %6.29
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1308
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.... Read more
- EPSS Score: %5.42
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1279
Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option).... Read more
Affected Products : masqmail- EPSS Score: %0.14
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1313
nullmailer 1.00RC5 and earlier allows local users to cause a denial of service via an email to a local user that does not exist, which generates an error that causes nullmailer to stop sending mail to all users.... Read more
Affected Products : nullmailer- EPSS Score: %0.08
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1315
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating... Read more
Affected Products : iplanet_web_server- EPSS Score: %2.08
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1210
Qualcomm Eudora 5.1.1, 5.2, and possibly other versions stores email attachments in a predictable location, which allows remote attackers to read arbitrary files via a link that loads an attachment with malicious script into a frame, which then executes t... Read more
Affected Products : eudora- EPSS Score: %0.38
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1220
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.... Read more
- EPSS Score: %19.18
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1295
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private c... Read more
Affected Products : java_virtual_machine- EPSS Score: %3.07
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1221
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.... Read more
- EPSS Score: %3.66
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1219
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).... Read more
- EPSS Score: %7.08
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1276
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.... Read more
- EPSS Score: %0.64
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1288
The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call.... Read more
Affected Products : java_virtual_machine- EPSS Score: %5.42
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025