Latest CVE Feed
-
7.5
HIGHCVE-2002-0546
Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.... Read more
Affected Products : winamp- EPSS Score: %1.05
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0536
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.... Read more
Affected Products : phpgroupware- EPSS Score: %0.82
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0359
xfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can mount or unmount xfs file systems, to gain root privileges.... Read more
Affected Products : irix- EPSS Score: %1.38
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0543
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.... Read more
Affected Products : abyss_web_server- EPSS Score: %10.26
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0570
The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.... Read more
- EPSS Score: %0.12
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0364
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."... Read more
- EPSS Score: %33.44
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0560
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.... Read more
- EPSS Score: %7.50
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0373
The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Pri... Read more
- EPSS Score: %1.71
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0615
The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation".... Read more
- EPSS Score: %11.40
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0366
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.... Read more
- EPSS Score: %0.48
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0572
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused ... Read more
- EPSS Score: %0.28
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0537
The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.... Read more
Affected Products : sws- EPSS Score: %1.27
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0372
Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored... Read more
Affected Products : windows_media_player- EPSS Score: %7.39
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0558
Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending in wildcard *.* characters.... Read more
Affected Products : typsoft_ftp_server- EPSS Score: %2.26
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0545
Cisco Aironet before 11.21 with Telnet enabled allows remote attackers to cause a denial of service (reboot) via a series of login attempts with invalid usernames and passwords.... Read more
- EPSS Score: %0.87
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0569
Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).... Read more
Affected Products : application_server- EPSS Score: %2.18
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0566
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.... Read more
- EPSS Score: %1.55
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0563
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5)... Read more
- EPSS Score: %34.45
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0573
Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be ... Read more
- EPSS Score: %47.42
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0623
Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".... Read more
Affected Products : commerce_server- EPSS Score: %17.28
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025