Latest CVE Feed
-
7.5
HIGHCVE-2002-0686
Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter.... Read more
Affected Products : iplanet_web_server- EPSS Score: %4.68
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0683
Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.... Read more
Affected Products : carello- EPSS Score: %0.60
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0680
Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been r... Read more
- EPSS Score: %5.24
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0667
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.... Read more
Affected Products : xpressa- EPSS Score: %2.20
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0685
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via... Read more
- EPSS Score: %1.32
- Published: Jul. 23, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0653
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entrie... Read more
Affected Products : mod_ssl- EPSS Score: %0.46
- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0676
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and s... Read more
Affected Products : mac_os_x- EPSS Score: %6.42
- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0665
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.... Read more
Affected Products : jrun- EPSS Score: %3.54
- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0637
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Typ... Read more
Affected Products : interscan_viruswall- EPSS Score: %3.82
- Published: Jul. 11, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1448
An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.... Read more
- EPSS Score: %1.40
- Published: Jul. 08, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0556
Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.... Read more
Affected Products : quik-serv_webserver- EPSS Score: %0.26
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0652
xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().... Read more
Affected Products : irix- EPSS Score: %6.84
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0554
webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.... Read more
Affected Products : informix_web_datablade- EPSS Score: %0.73
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0550
Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.... Read more
Affected Products : dynamic_guestbook- EPSS Score: %1.92
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0622
The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".... Read more
Affected Products : commerce_server- EPSS Score: %10.27
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0557
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrec... Read more
Affected Products : openbsd- EPSS Score: %0.53
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0547
Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field of an ID3v2 tag.... Read more
Affected Products : winamp- EPSS Score: %1.66
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0571
Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.... Read more
- EPSS Score: %0.84
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0551
Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.... Read more
Affected Products : dynamic_guestbook- EPSS Score: %1.92
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0541
Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HT... Read more
Affected Products : tivoli_storage_manager- EPSS Score: %4.11
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025