Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0300
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, which does not work around a limitation of JServ and do... Read more
Affected Products : gnujsp- EPSS Score: %5.11
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0282
DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path... Read more
Affected Products : dcp-portal- EPSS Score: %1.40
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0273
Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter.... Read more
Affected Products : cwmail- EPSS Score: %0.49
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0033
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.... Read more
- EPSS Score: %55.47
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0232
Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.... Read more
Affected Products : multi_router_traffic_grapher_cgi- EPSS Score: %1.61
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0236
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.... Read more
- EPSS Score: %7.28
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0239
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.... Read more
Affected Products : hanterm- EPSS Score: %0.27
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0245
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any reque... Read more
Affected Products : domino- EPSS Score: %0.74
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0377
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.... Read more
Affected Products : gaim- EPSS Score: %0.12
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0374
Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name.... Read more
- EPSS Score: %1.73
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0248
wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.... Read more
Affected Products : wmtv- EPSS Score: %0.15
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0247
Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges.... Read more
Affected Products : wmtv- EPSS Score: %0.05
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0155
Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.... Read more
- EPSS Score: %19.14
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0265
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file.... Read more
Affected Products : sawmill- EPSS Score: %0.21
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0253
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, caus... Read more
Affected Products : php- EPSS Score: %0.78
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0362
Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and a TLV type greater than 0x2711.... Read more
Affected Products : instant_messenger- EPSS Score: %4.76
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-0270
Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the u... Read more
Affected Products : opera_web_browser- EPSS Score: %0.28
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0254
ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains large height and width values, which causes the crash when viewed in Userdetails.... Read more
Affected Products : icq- EPSS Score: %0.98
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0259
InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.... Read more
Affected Products : miniportal- EPSS Score: %0.07
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0266
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.... Read more
Affected Products : texis- EPSS Score: %5.25
- Published: May. 29, 2002
- Modified: Apr. 03, 2025