Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2002-0308

    admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.... Read more

    Affected Products : admentor
    • EPSS Score: %0.43
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0306

    ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.... Read more

    Affected Products : avengers_news_system
    • EPSS Score: %1.00
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0277

    Add2it Mailman Free 1.73 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the list parameter.... Read more

    Affected Products : mailman_free
    • EPSS Score: %1.01
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2002-0293

    FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.... Read more

    Affected Products : omnipcx
    • EPSS Score: %0.07
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0302

    The Notify daemon for Symantec Enterprise Firewall (SEF) 6.5.x drops large alerts when SNMP is used as the transport, which could prevent some alerts from being sent in the event of an attack.... Read more

    Affected Products : enterprise_firewall
    • EPSS Score: %0.71
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0304

    Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.... Read more

    Affected Products : lil_http_server
    • EPSS Score: %0.95
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0272

    Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.... Read more

    Affected Products : linux mpg321
    • EPSS Score: %5.48
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0311

    Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.... Read more

    Affected Products : unixware openunix
    • EPSS Score: %3.13
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0193

    Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system f... Read more

    Affected Products : internet_explorer
    • EPSS Score: %45.78
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0155

    Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.... Read more

    • EPSS Score: %19.14
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-0355

    netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.... Read more

    Affected Products : irix
    • EPSS Score: %0.16
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-0169

    The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element... Read more

    • EPSS Score: %0.08
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0268

    Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.... Read more

    Affected Products : biologon
    • EPSS Score: %0.07
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-0234

    NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consume... Read more

    Affected Products : netscreen_screenos
    • EPSS Score: %0.08
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0250

    Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change th... Read more

    • EPSS Score: %8.76
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-0377

    Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.... Read more

    Affected Products : gaim
    • EPSS Score: %0.12
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0241

    NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.... Read more

    Affected Products : secure_access_control_server
    • EPSS Score: %0.19
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0251

    Buffer overflow in licq 1.0.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string of format string characters such as "%d".... Read more

    Affected Products : licq
    • EPSS Score: %5.48
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0244

    Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.... Read more

    Affected Products : atheos
    • EPSS Score: %1.92
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0238

    Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.... Read more

    Affected Products : rt314
    • EPSS Score: %0.85
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291573 Results