Latest CVE Feed
-
7.2
HIGHCVE-2002-0327
Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.... Read more
Affected Products : term- EPSS Score: %0.13
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0324
Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password ... Read more
Affected Products : graymatter- EPSS Score: %1.05
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0340
Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unau... Read more
Affected Products : windows_media_player- EPSS Score: %4.11
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0312
Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.... Read more
Affected Products : essentia_web_server- EPSS Score: %3.01
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0349
Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions.... Read more
Affected Products : tiny_personal_firewall- EPSS Score: %0.07
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0322
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.... Read more
Affected Products : messenger- EPSS Score: %0.72
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0344
Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.... Read more
Affected Products : liveupdate- EPSS Score: %1.15
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0345
Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.... Read more
Affected Products : norton_ghost- EPSS Score: %0.61
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0321
Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.... Read more
Affected Products : messenger- EPSS Score: %2.33
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0146
fetchmail email client before 5.9.10 does not properly limit the maximum number of messages available, which allows a remote IMAP server to overwrite memory via a message count that exceeds the boundaries of an array.... Read more
Affected Products : fetchmail- EPSS Score: %0.86
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0339
Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.... Read more
Affected Products : ios- EPSS Score: %2.26
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0379
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a l... Read more
Affected Products : uw-imap- EPSS Score: %29.90
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0323
comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.... Read more
Affected Products : scriptease_webserver- EPSS Score: %0.38
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0336
Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.... Read more
- EPSS Score: %7.31
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0318
FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.... Read more
Affected Products : freeradius- EPSS Score: %0.98
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0338
The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.... Read more
Affected Products : the_bat- EPSS Score: %9.00
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2002-0337
RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files.... Read more
Affected Products : realplayer- EPSS Score: %1.02
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0319
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.... Read more
Affected Products : pforum- EPSS Score: %8.22
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0347
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.... Read more
- EPSS Score: %7.64
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0341
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.... Read more
Affected Products : groupwise- EPSS Score: %0.17
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025