Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0275
Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.... Read more
Affected Products : falcon_web_server- EPSS Score: %0.53
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0285
Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms... Read more
Affected Products : outlook_express- EPSS Score: %6.99
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0295
Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.... Read more
Affected Products : omnipcx- EPSS Score: %0.06
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0283
Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data.... Read more
Affected Products : windows_xp- EPSS Score: %3.44
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0287
pforum 1.14 and earlier does not explicitly enable PHP magic quotes, which allows remote attackers to bypass authentication and gain administrator privileges via an SQL injection attack when the PHP server is not configured to use magic quotes by default.... Read more
Affected Products : pforum- EPSS Score: %0.69
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0309
SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to deter... Read more
Affected Products : enterprise_firewall- EPSS Score: %0.86
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0310
Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3... Read more
Affected Products : webnews- EPSS Score: %0.85
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0291
Dino's Webserver 1.2 allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via several large HTTP requests within a short time.... Read more
Affected Products : dinos_webserver- EPSS Score: %1.68
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0307
Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads ... Read more
Affected Products : avengers_news_system- EPSS Score: %5.58
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0294
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.... Read more
Affected Products : omnipcx- EPSS Score: %0.08
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0290
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.... Read more
Affected Products : webnews- EPSS Score: %3.74
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0303
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.... Read more
Affected Products : groupwise- EPSS Score: %0.04
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2002-0296
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.... Read more
Affected Products : tarantella_enterprise- EPSS Score: %0.15
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2002-0281
Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php.... Read more
Affected Products : dcp-portal- EPSS Score: %0.74
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0279
The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges.... Read more
Affected Products : hp-ux- EPSS Score: %0.13
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0297
Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.... Read more
Affected Products : scriptease_webserver- EPSS Score: %1.59
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0278
Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.... Read more
Affected Products : mailman_free- EPSS Score: %1.96
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0305
Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge.... Read more
Affected Products : p100s- EPSS Score: %0.67
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0280
Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply.... Read more
Affected Products : codeblue- EPSS Score: %16.39
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0300
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and do... Read more
Affected Products : gnujsp- EPSS Score: %5.11
- Published: May. 31, 2002
- Modified: Apr. 03, 2025