Latest CVE Feed
-
6.8
MEDIUMCVE-2002-0840
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page vis... Read more
- EPSS Score: %88.77
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0864
The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of S... Read more
- EPSS Score: %18.45
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1138
Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overw... Read more
- EPSS Score: %11.40
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1152
Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie across an unencrypted channel, which could allow remote attackers to steal the cookie via sniffing.... Read more
- EPSS Score: %0.91
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1154
anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web s... Read more
Affected Products : analog- EPSS Score: %0.67
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1153
IBM Websphere 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with long HTTP headers, such as "Host".... Read more
Affected Products : websphere_application_server- EPSS Score: %2.58
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0863
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Wea... Read more
Affected Products : windows_2000 windows_xp windows_nt windows_2000_terminal_services .net_windows_server- EPSS Score: %9.51
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0969
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Ful... Read more
- EPSS Score: %0.10
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-1165
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or... Read more
- EPSS Score: %2.90
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1137
Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a lon... Read more
- EPSS Score: %18.74
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1139
The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location... Read more
- EPSS Score: %20.17
- Published: Oct. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0705
The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.... Read more
- EPSS Score: %1.08
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0706
UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.... Read more
- EPSS Score: %0.47
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0707
The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.... Read more
- EPSS Score: %0.71
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0838
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript fi... Read more
- EPSS Score: %4.43
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0370
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Window... Read more
Affected Products : windows_xp winzip lotus_notes windows_me stuffit_expander keyview_viewing_sdk windows_98_plus_pack- EPSS Score: %32.27
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0708
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.... Read more
- EPSS Score: %3.78
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0709
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.... Read more
- EPSS Score: %0.35
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0694
The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files fol... Read more
Affected Products : windows_2000 windows_xp windows_98 windows_nt windows_98se windows_me windows_2000_terminal_services- EPSS Score: %28.96
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0399
Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the... Read more
Affected Products : tar- EPSS Score: %1.20
- Published: Oct. 10, 2002
- Modified: Apr. 03, 2025