Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2002-0702

    Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0.1rc8, with the NSUPDATE option enabled, allow remote malicious DNS servers to execute arbitrary code via format strings in a DNS serve... Read more

    Affected Products : dhcpd dhcp
    • EPSS Score: %37.65
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0369

    Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode.... Read more

    Affected Products : .net_framework
    • EPSS Score: %19.26
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2002-0435

    Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it ... Read more

    Affected Products : linux fileutils
    • EPSS Score: %0.07
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0448

    Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences.... Read more

    Affected Products : xerver
    • EPSS Score: %7.63
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0682

    Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.... Read more

    Affected Products : tomcat
    • EPSS Score: %66.60
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0641

    Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT que... Read more

    Affected Products : sql_server sql_server msde
    • EPSS Score: %16.41
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0677

    CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_I... Read more

    • EPSS Score: %19.03
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0674

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication.... Read more

    Affected Products : xpressa
    • EPSS Score: %0.07
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0678

    CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.... Read more

    • EPSS Score: %0.43
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1599

    DansGuardian before 2.4.5-1 allows remote attackers to bypass content filtering rules via hex-encoded URLs.... Read more

    Affected Products : dansguardian
    • EPSS Score: %0.97
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0670

    The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.... Read more

    Affected Products : xpressa
    • EPSS Score: %1.26
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0683

    Directory traversal vulnerability in Carello 1.3 allows remote attackers to execute programs on the server via a .. (dot dot) in the VBEXE parameter.... Read more

    Affected Products : carello
    • EPSS Score: %0.60
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0680

    Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been r... Read more

    • EPSS Score: %5.24
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0686

    Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter.... Read more

    Affected Products : iplanet_web_server
    • EPSS Score: %4.68
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0667

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.... Read more

    Affected Products : xpressa
    • EPSS Score: %2.20
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-0701

    ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was runni... Read more

    Affected Products : freebsd openbsd
    • EPSS Score: %0.14
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0685

    Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via... Read more

    • EPSS Score: %1.32
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0642

    The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permissio... Read more

    Affected Products : sql_server sql_server msde
    • EPSS Score: %75.06
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0687

    The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.... Read more

    Affected Products : zope
    • EPSS Score: %0.60
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0668

    The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows authenticated users to modify the Call Forwarding settings and hijack calls.... Read more

    Affected Products : xpressa
    • EPSS Score: %0.49
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 292100 Results