Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0305
Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge.... Read more
Affected Products : p100s- EPSS Score: %0.67
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0286
The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produ... Read more
Affected Products : sitenews- EPSS Score: %0.72
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0278
Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.... Read more
Affected Products : mailman_free- EPSS Score: %1.96
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0280
Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply.... Read more
Affected Products : codeblue- EPSS Score: %16.39
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0169
The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element... Read more
- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0268
Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.... Read more
Affected Products : biologon- EPSS Score: %0.07
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0251
Buffer overflow in licq 1.0.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string of format string characters such as "%d".... Read more
Affected Products : licq- EPSS Score: %5.48
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0250
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change th... Read more
Affected Products : advancestack_10base-t_switching_hub_j3200a advancestack_10base-t_switching_hub_j3201a advancestack_10base-t_switching_hub_j3202a advancestack_10base-t_switching_hub_j3203a advancestack_10base-t_switching_hub_j3204a advancestack_10base-t_switching_hub_j3205a advancestack_10base-t_switching_hub_j3210a- EPSS Score: %8.76
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0244
Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.... Read more
Affected Products : atheos- EPSS Score: %1.92
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0241
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.... Read more
Affected Products : secure_access_control_server- EPSS Score: %0.19
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0238
Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.... Read more
Affected Products : rt314- EPSS Score: %0.85
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0377
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.... Read more
Affected Products : gaim- EPSS Score: %0.12
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0189
Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.... Read more
Affected Products : internet_explorer- EPSS Score: %15.37
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0255
The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.... Read more
Affected Products : netdsl- EPSS Score: %0.49
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0256
The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, which causes a large number of login failures and causes the telnet service to stop.... Read more
Affected Products : netdsl- EPSS Score: %4.19
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0249
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.... Read more
Affected Products : http_server- EPSS Score: %2.83
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0155
Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.... Read more
- EPSS Score: %19.14
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0237
Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a flood of large ICMP ping... Read more
- EPSS Score: %3.24
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0240
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.... Read more
Affected Products : http_server- EPSS Score: %1.69
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0235
Castelle FaxPress, possibly 6.3 and other versions, when configured to use the Network print queue, allows attackers to obtain the username and password by submitting an incorrect login, which causes Faxpress to leak the correct username and password in p... Read more
Affected Products : faxpress- EPSS Score: %0.80
- Published: May. 29, 2002
- Modified: Apr. 03, 2025