Latest CVE Feed
-
5.0
MEDIUMCVE-2002-0256
The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, which causes a large number of login failures and causes the telnet service to stop.... Read more
Affected Products : netdsl- EPSS Score: %4.19
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0237
Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a flood of large ICMP ping... Read more
- EPSS Score: %3.24
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0258
Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or f... Read more
- EPSS Score: %0.75
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0261
Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.... Read more
Affected Products : miniportal- EPSS Score: %3.16
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0250
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allows unauthorized users to bypass authentication via a direct HTTP request to the web_access.html file, which allows the user to change th... Read more
Affected Products : advancestack_10base-t_switching_hub_j3200a advancestack_10base-t_switching_hub_j3201a advancestack_10base-t_switching_hub_j3202a advancestack_10base-t_switching_hub_j3203a advancestack_10base-t_switching_hub_j3204a advancestack_10base-t_switching_hub_j3205a advancestack_10base-t_switching_hub_j3210a- EPSS Score: %8.76
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0251
Buffer overflow in licq 1.0.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string of format string characters such as "%d".... Read more
Affected Products : licq- EPSS Score: %5.48
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0193
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system f... Read more
Affected Products : internet_explorer- EPSS Score: %45.78
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0268
Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.... Read more
Affected Products : biologon- EPSS Score: %0.07
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0234
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consume... Read more
Affected Products : netscreen_screenos- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0169
The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element... Read more
- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0355
netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.... Read more
Affected Products : irix- EPSS Score: %0.16
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0241
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.... Read more
Affected Products : secure_access_control_server- EPSS Score: %0.19
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0377
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.... Read more
Affected Products : gaim- EPSS Score: %0.12
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0244
Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.... Read more
Affected Products : atheos- EPSS Score: %1.92
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0238
Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.... Read more
Affected Products : rt314- EPSS Score: %0.85
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0249
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.... Read more
Affected Products : http_server- EPSS Score: %2.83
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0259
InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.... Read more
Affected Products : miniportal- EPSS Score: %0.07
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0235
Castelle FaxPress, possibly 6.3 and other versions, when configured to use the Network print queue, allows attackers to obtain the username and password by submitting an incorrect login, which causes Faxpress to leak the correct username and password in p... Read more
Affected Products : faxpress- EPSS Score: %0.80
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0267
preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin command, which causes the Status line to be entered into ... Read more
Affected Products : sips- EPSS Score: %1.19
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0246
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs suc... Read more
Affected Products : unixware- EPSS Score: %0.24
- Published: May. 29, 2002
- Modified: Apr. 03, 2025