Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0375
Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter.... Read more
Affected Products : sgdynamo- EPSS Score: %3.83
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0236
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.... Read more
- EPSS Score: %7.28
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0033
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.... Read more
- EPSS Score: %55.47
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0266
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.... Read more
Affected Products : texis- EPSS Score: %5.25
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0248
wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.... Read more
Affected Products : wmtv- EPSS Score: %0.15
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0374
Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name.... Read more
- EPSS Score: %1.73
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0256
The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, which causes a large number of login failures and causes the telnet service to stop.... Read more
Affected Products : netdsl- EPSS Score: %4.19
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0255
The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.... Read more
Affected Products : netdsl- EPSS Score: %0.49
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0189
Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.... Read more
Affected Products : internet_explorer- EPSS Score: %15.37
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-1447
Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.... Read more
Affected Products : vpn_client- EPSS Score: %0.41
- Published: May. 28, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1641
Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors.... Read more
- EPSS Score: %13.22
- Published: May. 27, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1340
Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service.... Read more
Affected Products : ipc_at_chip_telnetd_server- EPSS Score: %1.79
- Published: May. 21, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1334
Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrary files by creating a block and specifying the target file as the source URL.... Read more
Affected Products : phpslash- EPSS Score: %3.92
- Published: May. 19, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-1280
Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash).... Read more
Affected Products : realsecure_event_collector- EPSS Score: %0.41
- Published: May. 17, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0206
index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.... Read more
Affected Products : php-nuke- EPSS Score: %0.22
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0203
ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.... Read more
Affected Products : tarantella_enterprise- EPSS Score: %0.71
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0199
Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes.... Read more
Affected Products : shoutcast_server- EPSS Score: %1.82
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0229
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.... Read more
Affected Products : php- EPSS Score: %7.72
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1056
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary script... Read more
- EPSS Score: %16.38
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0185
mod_python version 2.7.6 and earlier allows a module indirectly imported by a published module to then be accessed via the publisher, which allows remote attackers to call possibly dangerous functions from the imported module.... Read more
Affected Products : mod_python- EPSS Score: %4.63
- Published: May. 16, 2002
- Modified: Apr. 03, 2025