Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2002-0325

    Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.... Read more

    Affected Products : badblue
    • EPSS Score: %6.72
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0381

    The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadca... Read more

    Affected Products : freebsd netbsd openbsd
    • EPSS Score: %0.78
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0315

    fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.... Read more

    Affected Products : grokster kazaa morpheus
    • EPSS Score: %0.86
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0330

    Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag.... Read more

    Affected Products : openbb
    • EPSS Score: %6.96
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0321

    Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.... Read more

    Affected Products : messenger
    • EPSS Score: %2.33
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0327

    Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.... Read more

    Affected Products : term
    • EPSS Score: %0.13
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0322

    Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.... Read more

    Affected Products : messenger
    • EPSS Score: %0.72
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-0349

    Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions.... Read more

    Affected Products : tiny_personal_firewall
    • EPSS Score: %0.07
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0344

    Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.... Read more

    Affected Products : liveupdate
    • EPSS Score: %1.15
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0345

    Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.... Read more

    Affected Products : norton_ghost
    • EPSS Score: %0.61
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0357

    Unknown vulnerability in rpc.passwd in the nfs.sw.nis subsystem of SGI IRIX 6.5.15 and earlier allows local users to gain root privileges.... Read more

    Affected Products : irix
    • EPSS Score: %0.09
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0587

    Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters.... Read more

    Affected Products : aol_server
    • EPSS Score: %1.90
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0599

    Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen.... Read more

    Affected Products : blahz-dns
    • EPSS Score: %4.75
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0598

    Format string vulnerability in Foundstone FScan 1.12 with banner grabbing enabled allows remote attackers to execute arbitrary code on the scanning system via format string specifiers in the server banner.... Read more

    Affected Products : fscan
    • EPSS Score: %4.33
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0593

    Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.... Read more

    Affected Products : mozilla navigator communicator
    • EPSS Score: %3.40
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0594

    Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.... Read more

    Affected Products : mozilla navigator galeon_browser
    • EPSS Score: %1.09
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0380

    Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS packet.... Read more

    Affected Products : linux tcpdump
    • EPSS Score: %4.37
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0401

    SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.... Read more

    Affected Products : debian_linux ethereal
    • EPSS Score: %5.82
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0402

    Buffer overflow in X11 dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code while Ethereal is parsing keysyms.... Read more

    Affected Products : ethereal
    • EPSS Score: %2.68
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0368

    The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."... Read more

    Affected Products : exchange_server
    • EPSS Score: %18.09
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291526 Results