Latest CVE Feed
-
7.5
HIGHCVE-2002-0199
Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes.... Read more
Affected Products : shoutcast_server- EPSS Score: %1.82
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0203
ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.... Read more
Affected Products : tarantella_enterprise- EPSS Score: %0.71
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0229
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.... Read more
Affected Products : php- EPSS Score: %7.72
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1056
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary script... Read more
- EPSS Score: %16.38
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0172
/dev/ipfilter on SGI IRIX 6.5 is installed by /dev/MAKEDEV with insecure default permissions (644), which could allow a local user to cause a denial of service (traffic disruption).... Read more
Affected Products : irix- EPSS Score: %0.22
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0222
Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.... Read more
Affected Products : eserv- EPSS Score: %0.72
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0206
index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.... Read more
Affected Products : php-nuke- EPSS Score: %0.22
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0227
KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.... Read more
- EPSS Score: %4.72
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0200
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.... Read more
Affected Products : cyberstop_web_server- EPSS Score: %2.57
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0184
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.... Read more
- EPSS Score: %0.21
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0230
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.... Read more
Affected Products : faq-o-matic- EPSS Score: %4.38
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0215
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.... Read more
Affected Products : agora.cgi- EPSS Score: %8.20
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0216
userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.... Read more
Affected Products : xoops- EPSS Score: %0.83
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2002-0211
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable temporary "gunzip" program before executing it, which could allow local users to execute arbitrary commands by modifying the program before i... Read more
Affected Products : tarantella_enterprise- EPSS Score: %0.17
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0205
Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter.... Read more
Affected Products : plumtree_corporate_portal- EPSS Score: %0.74
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0207
Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds the actual length of the header.... Read more
- EPSS Score: %11.10
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0204
Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to execute arbitrary code via a long command.... Read more
Affected Products : chess- EPSS Score: %3.21
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0218
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.... Read more
- EPSS Score: %0.10
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0212
The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernames and makes it easier to conduct a brute force attack.... Read more
Affected Products : hosting_controller- EPSS Score: %0.74
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0201
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.... Read more
Affected Products : cyberstop_web_server- EPSS Score: %3.04
- Published: May. 16, 2002
- Modified: Apr. 03, 2025