Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2002-0408

    htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard... Read more

    Affected Products : domino
    • EPSS Score: %1.08
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0433

    Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.... Read more

    Affected Products : pi3web
    • EPSS Score: %0.68
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0434

    Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.... Read more

    Affected Products : directory.php
    • EPSS Score: %2.73
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0406

    Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections to the server without providing login credentials, which prevents other users from being able to log in.... Read more

    Affected Products : sphereserver
    • EPSS Score: %4.72
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0449

    Buffer overflow in webpsvc.exe for Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long argument to webplus.exe program, which triggers the overflow in webpsvc.exe.... Read more

    Affected Products : web\+_server
    • EPSS Score: %13.01
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0445

    article.php in PHP FirstPost 0.1 allows allows remote attackers to obtain the full pathname of the server via an invalid post number in the post parameter, which leaks the pathname in an error message.... Read more

    Affected Products : php_firstpost
    • EPSS Score: %0.52
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0394

    Red-M 1050 (Bluetooth Access Point) uses case insensitive passwords, which makes it easier for attackers to conduct a brute force guessing attack due to the smaller space of possible passwords.... Read more

    Affected Products : 1050ap_lan_acess_point
    • EPSS Score: %0.70
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0446

    categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message.... Read more

    Affected Products : black_tie_project
    • EPSS Score: %0.81
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0714

    FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.... Read more

    Affected Products : squid
    • EPSS Score: %0.17
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0713

    Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (... Read more

    Affected Products : squid
    • EPSS Score: %1.34
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0409

    orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.... Read more

    Affected Products : .net_framework
    • EPSS Score: %34.23
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0703

    An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data.... Read more

    Affected Products : digest-md5
    • EPSS Score: %0.59
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0393

    Buffer overflow in Red-M 1050 (Bluetooth Access Point) management web interface allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long administration password.... Read more

    Affected Products : 1050ap_lan_acess_point
    • EPSS Score: %3.15
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0436

    sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %3.93
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0688

    ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.... Read more

    Affected Products : zope
    • EPSS Score: %0.60
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0642

    The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permissio... Read more

    Affected Products : sql_server sql_server msde
    • EPSS Score: %75.06
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0687

    The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.... Read more

    Affected Products : zope
    • EPSS Score: %0.60
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0668

    The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and hijack calls.... Read more

    Affected Products : xpressa
    • EPSS Score: %0.49
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2002-0671

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing... Read more

    Affected Products : xpressa xpressa_firmware
    • EPSS Score: %0.51
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0641

    Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT que... Read more

    Affected Products : sql_server sql_server msde
    • EPSS Score: %16.41
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291890 Results