Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0341
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.... Read more
Affected Products : groupwise- EPSS Score: %0.17
- Published: Jun. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0609
Vulnerability in HP MPE/iX 6.0 through 7.0 allows attackers to cause a denial of service (system failure with "SA1457 out of i_port_timeout.fix_up_message_frame") via malformed IP packets.... Read more
Affected Products : mpe_ix- EPSS Score: %1.52
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0591
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.... Read more
Affected Products : instant_messenger- EPSS Score: %9.74
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0608
Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner.... Read more
Affected Products : matu_ftp- EPSS Score: %3.81
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0580
WorkforceROI Xpede 4.1 allows remote attackers to obtain the database username via a request to datasource.asp, which leaks the username in a form and allows the attacker to more easily conduct brute force password guessing attacks.... Read more
Affected Products : xpede- EPSS Score: %0.85
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0584
WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for each new timesheet.... Read more
Affected Products : xpede- EPSS Score: %2.26
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0585
Unknown vulnerability in ndd for HP-UX 11.11 with certain TRANSPORT patches allows attackers to cause a denial of service.... Read more
Affected Products : hp-ux- EPSS Score: %0.71
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0586
Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via the Error or Notice parameters.... Read more
Affected Products : aol_server- EPSS Score: %1.98
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0579
WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.... Read more
Affected Products : xpede- EPSS Score: %1.88
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0602
Snapgear Lite+ firewall 1.5.4 and 1.5.3 allows remote attackers to cause a denial of service (crash) via a large number of connections to (1) the HTTP web management port, or (2) the PPTP port.... Read more
Affected Products : snapgear_lite\+_firewall- EPSS Score: %1.12
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0605
Buffer overflow in Flash OCX for Macromedia Flash 6 revision 23 (6,0,23,0) allows remote attackers to execute arbitrary code via a long movie parameter.... Read more
Affected Products : flash_player- EPSS Score: %12.52
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0606
Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long commands such as login.... Read more
Affected Products : 3cdaemon- EPSS Score: %5.52
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0613
dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.... Read more
Affected Products : dnstools- EPSS Score: %3.64
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0603
Snapgear Lite+ firewall 1.5.3 allows remote attackers to cause a denial of service (IPSEC crash) via a zero length packet to UDP port 500.... Read more
Affected Products : snapgear_lite\+_firewall- EPSS Score: %0.91
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0590
Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and steal cookies as other IcrediBB users via the (1) title or (2) body of posts.... Read more
Affected Products : icredibb- EPSS Score: %3.06
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0577
Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.... Read more
Affected Products : hp-ux- EPSS Score: %0.10
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0607
members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL.... Read more
Affected Products : snitz_forums_2000- EPSS Score: %1.74
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0587
Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to cause a denial of service or execute arbitrary code via the Error or Notice parameters.... Read more
Affected Products : aol_server- EPSS Score: %1.90
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0357
Unknown vulnerability in rpc.passwd in the nfs.sw.nis subsystem of SGI IRIX 6.5.15 and earlier allows local users to gain root privileges.... Read more
Affected Products : irix- EPSS Score: %0.09
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0599
Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesting CGI programs such as dostuff.php instead of going through the login screen.... Read more
Affected Products : blahz-dns- EPSS Score: %4.75
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025