Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2002-0128

    cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long argument.... Read more

    Affected Products : sambar_server
    • EPSS Score: %8.65
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-0138

    CDRDAO 1.1.4 and 1.1.5 allows local users to read arbitrary files via the show-data command.... Read more

    Affected Products : cdrdao
    • EPSS Score: %0.12
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0133

    Buffer overflows in Avirt Gateway Suite 4.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long header fields to the HTTP proxy, or (2) a long string to the telnet proxy.... Read more

    • EPSS Score: %3.78
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0134

    Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitrary commands via a "dos" command.... Read more

    Affected Products : avirt_gateway_suite
    • EPSS Score: %1.33
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0098

    Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner.... Read more

    Affected Products : boozt_standard
    • EPSS Score: %2.21
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0123

    MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 and earlier, and possibly 3.5.3, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.... Read more

    Affected Products : web_server_4d_ecommerce
    • EPSS Score: %0.99
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-0113

    EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for... Read more

    Affected Products : networker
    • EPSS Score: %0.05
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0126

    Buffer overflow in BlackMoon FTP Server 1.0 through 1.5 allows remote attackers to execute arbitrary code via a long argument to (1) USER, (2) PASS, or (3) CWD.... Read more

    Affected Products : blackmoon_ftp_server
    • EPSS Score: %3.99
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0104

    AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump.... Read more

    Affected Products : aftpd
    • EPSS Score: %0.92
    • Published: Mar. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2000-1210

    Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.... Read more

    Affected Products : tomcat
    • EPSS Score: %3.92
    • Published: Mar. 22, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0061

    Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell... Read more

    Affected Products : http_server
    • EPSS Score: %83.65
    • Published: Mar. 21, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0076

    Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.... Read more

    Affected Products : jre sdk jdk virtual_machine java_jre-jdk
    • EPSS Score: %1.08
    • Published: Mar. 19, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0092

    CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) via the diff capability.... Read more

    Affected Products : cvs
    • EPSS Score: %1.27
    • Published: Mar. 15, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0058

    Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 thr... Read more

    Affected Products : jre sdk jdk virtual_machine
    • EPSS Score: %2.81
    • Published: Mar. 15, 2002
    • Modified: Apr. 03, 2025
  • 7.6

    HIGH
    CVE-2002-0070

    Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.... Read more

    • EPSS Score: %26.11
    • Published: Mar. 15, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0083

    Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.... Read more

    • EPSS Score: %4.08
    • Published: Mar. 15, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0084

    Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %3.23
    • Published: Mar. 15, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0090

    Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.... Read more

    Affected Products : solaris
    • EPSS Score: %0.14
    • Published: Mar. 15, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0082

    The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code ... Read more

    Affected Products : apache-ssl mod_ssl
    • EPSS Score: %2.51
    • Published: Mar. 15, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0089

    Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %0.08
    • Published: Mar. 15, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291863 Results