Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2002-0571

    Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.... Read more

    Affected Products : database_server oracle9i
    • EPSS Score: %0.84
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0551

    Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.... Read more

    Affected Products : dynamic_guestbook
    • EPSS Score: %1.92
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0541

    Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HT... Read more

    Affected Products : tivoli_storage_manager
    • EPSS Score: %4.11
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0538

    FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server's "FTP PORT" responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the "FTP bounce" vulnerability.... Read more

    • EPSS Score: %2.90
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0567

    Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.... Read more

    Affected Products : database_server oracle8i oracle9i
    • EPSS Score: %1.76
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0549

    Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users.... Read more

    Affected Products : anthill
    • EPSS Score: %0.85
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0652

    xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().... Read more

    Affected Products : irix
    • EPSS Score: %6.84
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0359

    xfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can mount or unmount xfs file systems, to gain root privileges.... Read more

    Affected Products : irix
    • EPSS Score: %1.38
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0553

    Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges to SunShop by injecting the script into fields during new customer registration.... Read more

    Affected Products : sunshop_shopping_cart
    • EPSS Score: %3.06
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0540

    Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.... Read more

    • EPSS Score: %7.41
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0543

    Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.... Read more

    Affected Products : abyss_web_server
    • EPSS Score: %10.26
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0546

    Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.... Read more

    Affected Products : winamp
    • EPSS Score: %1.05
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0536

    PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.... Read more

    Affected Products : phpgroupware
    • EPSS Score: %0.82
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0574

    Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which preven... Read more

    Affected Products : freebsd
    • EPSS Score: %1.10
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0555

    IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.... Read more

    Affected Products : informix_web_datablade
    • EPSS Score: %1.20
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0544

    Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.... Read more

    Affected Products : abyss_web_server
    • EPSS Score: %0.13
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0621

    Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package... Read more

    Affected Products : commerce_server
    • EPSS Score: %16.67
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0623

    Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".... Read more

    Affected Products : commerce_server
    • EPSS Score: %17.28
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0545

    Cisco Aironet before 11.21 with Telnet enabled allows remote attackers to cause a denial of service (reboot) via a series of login attempts with invalid usernames and passwords.... Read more

    Affected Products : aironet_ap350 aironet_ap340
    • EPSS Score: %0.87
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0563

    The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5)... Read more

    • EPSS Score: %34.45
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291641 Results