Latest CVE Feed
-
1.2
LOWCVE-2002-0435
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it ... Read more
- EPSS Score: %0.07
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0448
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences.... Read more
Affected Products : xerver- EPSS Score: %7.63
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0446
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message.... Read more
Affected Products : black_tie_project- EPSS Score: %0.81
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0436
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.... Read more
- EPSS Score: %3.93
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0715
Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.... Read more
Affected Products : squid- EPSS Score: %0.40
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0685
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via... Read more
- EPSS Score: %1.32
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0682
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.... Read more
Affected Products : tomcat- EPSS Score: %66.60
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.... Read more
- EPSS Score: %0.43
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0641
Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT que... Read more
- EPSS Score: %16.41
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0624
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, ... Read more
- EPSS Score: %7.20
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1599
DansGuardian before 2.4.5-1 allows remote attackers to bypass content filtering rules via hex-encoded URLs.... Read more
Affected Products : dansguardian- EPSS Score: %0.97
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0674
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication.... Read more
Affected Products : xpressa- EPSS Score: %0.07
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0670
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.... Read more
Affected Products : xpressa- EPSS Score: %1.26
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0677
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_I... Read more
- EPSS Score: %19.03
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0675
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone.... Read more
Affected Products : xpressa- EPSS Score: %0.16
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0643
The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encr... Read more
- EPSS Score: %0.82
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0688
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.... Read more
Affected Products : zope- EPSS Score: %0.60
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0683
Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.... Read more
Affected Products : carello- EPSS Score: %0.60
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0686
Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter.... Read more
Affected Products : iplanet_web_server- EPSS Score: %4.68
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0681
Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.... Read more
Affected Products : goahead_webserver- EPSS Score: %7.31
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025