Latest CVE Feed
-
7.2
HIGHCVE-2002-0678
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.... Read more
- EPSS Score: %0.43
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0624
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, ... Read more
- EPSS Score: %7.20
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2002-0671
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing... Read more
- EPSS Score: %0.51
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0672
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null.... Read more
Affected Products : xpressa- EPSS Score: %0.16
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0685
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via... Read more
- EPSS Score: %1.32
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0688
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.... Read more
Affected Products : zope- EPSS Score: %0.60
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0682
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.... Read more
Affected Products : tomcat- EPSS Score: %66.60
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0641
Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT que... Read more
- EPSS Score: %16.41
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0687
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.... Read more
Affected Products : zope- EPSS Score: %0.60
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0668
The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and hijack calls.... Read more
Affected Products : xpressa- EPSS Score: %0.49
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0642
The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permissio... Read more
- EPSS Score: %75.06
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0676
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and s... Read more
Affected Products : mac_os_x- EPSS Score: %6.42
- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0637
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Typ... Read more
Affected Products : interscan_viruswall- EPSS Score: %3.82
- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0665
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.... Read more
Affected Products : jrun- EPSS Score: %3.54
- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0653
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entrie... Read more
Affected Products : mod_ssl- EPSS Score: %0.46
- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1448
An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.... Read more
- EPSS Score: %1.40
- Published: Jul. 08, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0652
xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().... Read more
Affected Products : irix- EPSS Score: %6.84
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0554
webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.... Read more
Affected Products : informix_web_datablade- EPSS Score: %0.73
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0550
Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.... Read more
Affected Products : dynamic_guestbook- EPSS Score: %1.92
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0622
The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".... Read more
Affected Products : commerce_server- EPSS Score: %10.27
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025