Latest CVE Feed
-
7.5
HIGHCVE-2002-1374
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first c... Read more
- EPSS Score: %25.36
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1360
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to ... Read more
- EPSS Score: %4.13
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1356
Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages... Read more
- EPSS Score: %2.05
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1376
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibl... Read more
- EPSS Score: %3.02
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1382
Macromedia Flash Player before 6.0.65.0 allows remote attackers to execute arbitrary code via certain malformed data headers in Shockwave Flash file format (SWF) files, a different issue than CAN-2002-0846.... Read more
Affected Products : flash_player- EPSS Score: %15.35
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1296
Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.... Read more
- EPSS Score: %0.03
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1643
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simu... Read more
Affected Products : helix_universal_server- EPSS Score: %81.94
- Published: Dec. 19, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1342
Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands.... Read more
Affected Products : smb2www- EPSS Score: %0.98
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1340
The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception.... Read more
Affected Products : office_web_components- EPSS Score: %14.07
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1354
Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.... Read more
Affected Products : typsoft_ftp_server- EPSS Score: %0.36
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1262
Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files.... Read more
Affected Products : internet_explorer- EPSS Score: %11.53
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2002-1341
Cross-site scripting (XSS) vulnerability in read_body.php for SquirrelMail 1.2.10, 1.2.9, and earlier allows remote attackers to insert script and HTML via the (1) mailbox and (2) passed_id parameters.... Read more
- EPSS Score: %2.70
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1344
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.... Read more
- EPSS Score: %0.76
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1158
Buffer overflow in the irw_through function for Canna 3.5b2 and earlier allows local users to execute arbitrary code as the bin user.... Read more
Affected Products : canna- EPSS Score: %0.08
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1255
Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 20... Read more
Affected Products : outlook- EPSS Score: %14.02
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-1159
Canna 3.6 and earlier does not properly validate requests, which allows remote attackers to cause a denial of service or information leak.... Read more
- EPSS Score: %1.27
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2002-1347
Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during ... Read more
- EPSS Score: %9.98
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1338
The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files.... Read more
Affected Products : office_web_components- EPSS Score: %24.40
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1339
The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files.... Read more
Affected Products : office_web_components- EPSS Score: %14.07
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1349
Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).... Read more
- EPSS Score: %0.30
- Published: Dec. 18, 2002
- Modified: Apr. 03, 2025