Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.6

    MEDIUM
    CVE-2002-0675

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone.... Read more

    Affected Products : xpressa
    • EPSS Score: %0.16
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0687

    The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.... Read more

    Affected Products : zope
    • EPSS Score: %0.60
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0642

    The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permissio... Read more

    Affected Products : sql_server sql_server msde
    • EPSS Score: %75.06
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0668

    The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and hijack calls.... Read more

    Affected Products : xpressa
    • EPSS Score: %0.49
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-0643

    The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encr... Read more

    Affected Products : sql_server sql_server data_engine
    • EPSS Score: %0.82
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0624

    Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, ... Read more

    Affected Products : sql_server sql_server msde
    • EPSS Score: %7.20
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2002-0671

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing... Read more

    Affected Products : xpressa xpressa_firmware
    • EPSS Score: %0.51
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0685

    Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via... Read more

    • EPSS Score: %1.32
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0641

    Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT que... Read more

    Affected Products : sql_server sql_server msde
    • EPSS Score: %16.41
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0688

    ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.... Read more

    Affected Products : zope
    • EPSS Score: %0.60
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0676

    SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and s... Read more

    Affected Products : mac_os_x
    • EPSS Score: %6.42
    • Published: Jul. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0637

    InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Typ... Read more

    Affected Products : interscan_viruswall
    • EPSS Score: %3.82
    • Published: Jul. 11, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0665

    Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.... Read more

    Affected Products : jrun
    • EPSS Score: %3.54
    • Published: Jul. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2002-0653

    Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entrie... Read more

    Affected Products : mod_ssl
    • EPSS Score: %0.46
    • Published: Jul. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1448

    An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.... Read more

    Affected Products : cajun_m770-atm cajun_p130 cajun_p330
    • EPSS Score: %1.40
    • Published: Jul. 08, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0556

    Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.... Read more

    Affected Products : quik-serv_webserver
    • EPSS Score: %0.26
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0622

    The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".... Read more

    Affected Products : commerce_server
    • EPSS Score: %10.27
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0557

    Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrec... Read more

    Affected Products : openbsd
    • EPSS Score: %0.53
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0547

    Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field of an ID3v2 tag.... Read more

    Affected Products : winamp
    • EPSS Score: %1.66
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0571

    Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.... Read more

    Affected Products : database_server oracle9i
    • EPSS Score: %0.84
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291562 Results