Latest CVE Feed
-
7.5
HIGHCVE-2002-0345
Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.... Read more
Affected Products : norton_ghost- EPSS Score: %0.61
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0344
Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.... Read more
Affected Products : liveupdate- EPSS Score: %1.15
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0321
Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.... Read more
Affected Products : messenger- EPSS Score: %2.33
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0349
Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions.... Read more
Affected Products : tiny_personal_firewall- EPSS Score: %0.07
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0327
Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.... Read more
Affected Products : term- EPSS Score: %0.13
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0352
Phorum 3.3.2 allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the stats.php program, which does not require authentication.... Read more
Affected Products : phorum- EPSS Score: %0.58
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0315
fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.... Read more
- EPSS Score: %0.86
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0330
Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag.... Read more
Affected Products : openbb- EPSS Score: %6.96
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0381
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadca... Read more
- EPSS Score: %0.78
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0323
comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.... Read more
Affected Products : scriptease_webserver- EPSS Score: %0.38
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0331
Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request.... Read more
Affected Products : bpm_studio_pro- EPSS Score: %3.06
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0314
fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.... Read more
- EPSS Score: %0.74
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0317
Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter.... Read more
Affected Products : gator- EPSS Score: %0.44
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0354
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result us... Read more
- EPSS Score: %0.38
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0335
Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request.... Read more
- EPSS Score: %8.65
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0348
service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.... Read more
- EPSS Score: %5.59
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0313
Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.... Read more
Affected Products : essentia_web_server- EPSS Score: %10.21
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0328
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.... Read more
Affected Products : ikonboard- EPSS Score: %3.22
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0326
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.... Read more
Affected Products : badblue- EPSS Score: %0.72
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0343
Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.... Read more
Affected Products : hotline_connect- EPSS Score: %0.07
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025