Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2002-0002

    Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.... Read more

    • EPSS Score: %14.92
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0046

    Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of fragmented ICMP packets that generate an ICMP TTL Exceeded response, which includes portions of the memory in the response packet.... Read more

    Affected Products : linux_kernel linux
    • EPSS Score: %1.20
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0008

    Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to ent... Read more

    Affected Products : bugzilla
    • EPSS Score: %2.14
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0009

    show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pulldown menu.... Read more

    Affected Products : bugzilla
    • EPSS Score: %0.86
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0010

    Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter i... Read more

    Affected Products : bugzilla
    • EPSS Score: %3.71
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0007

    CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.... Read more

    Affected Products : bugzilla
    • EPSS Score: %1.84
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0047

    CIPE VPN package before 1.3.0-3 allows remote attackers to cause a denial of service (crash) via a short malformed packet.... Read more

    Affected Products : cipe
    • EPSS Score: %0.74
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0043

    sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.... Read more

    Affected Products : linux sudo
    • EPSS Score: %0.19
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0045

    slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by A... Read more

    Affected Products : linux openldap
    • EPSS Score: %3.24
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2001-1457

    Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.... Read more

    Affected Products : crazywwwboard
    • EPSS Score: %6.03
    • Published: Jan. 30, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-1999-1081

    Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.... Read more

    Affected Products : web_server
    • EPSS Score: %1.77
    • Published: Jan. 15, 2002
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2001-0887

    xSANE 0.81 and earlier allows local users to modify files of other xSANE users via a symlink attack on temporary files.... Read more

    Affected Products : linux xsane
    • EPSS Score: %0.08
    • Published: Jan. 15, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-1999-1091

    UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.... Read more

    Affected Products : tin rtin
    • EPSS Score: %0.52
    • Published: Jan. 15, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0077

    Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the pop... Read more

    Affected Products : internet_explorer
    • EPSS Score: %8.14
    • Published: Jan. 13, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2003-0061

    Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a long LANG environment variable.... Read more

    Affected Products : hp-ux
    • EPSS Score: %0.08
    • Published: Jan. 11, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1596

    Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (router crash) via an HTTP request with large headers.... Read more

    Affected Products : sn_5420_storage_router_firmware
    • EPSS Score: %0.84
    • Published: Jan. 09, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1597

    Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (halt) via a fragmented packet to the Gigabit interface.... Read more

    Affected Products : sn_5420_storage_router_firmware
    • EPSS Score: %1.00
    • Published: Jan. 09, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1600

    Directory traversal vulnerability in Mike Spice's My Classifieds (classifieds.cgi) before 1.3 allows remote attackers to overwrite arbitrary files via the category parameter.... Read more

    Affected Products : my_classifieds
    • EPSS Score: %1.16
    • Published: Jan. 09, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-1595

    Cisco SN 5420 Storage Router 1.1(5) and earlier allows attackers to read configuration files without authorization.... Read more

    Affected Products : sn_5420_storage_router_firmware
    • EPSS Score: %0.39
    • Published: Jan. 09, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-1594

    Buffer overflow in (1) grpck and (2) pwck, if installed setuid on a system as recommended in some AIX documentation, may allow local users to gain privileges via a long command line argument.... Read more

    Affected Products : grpck pwck
    • EPSS Score: %0.14
    • Published: Jan. 02, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291788 Results