Latest CVE Feed
-
4.6
MEDIUMCVE-2002-0113
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for... Read more
Affected Products : networker- EPSS Score: %0.05
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-0109
Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router ... Read more
- EPSS Score: %0.76
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0102
Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters.... Read more
- EPSS Score: %0.56
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0098
Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner.... Read more
Affected Products : boozt_standard- EPSS Score: %2.21
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0103
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.... Read more
- EPSS Score: %0.09
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0106
BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name.... Read more
Affected Products : weblogic_server- EPSS Score: %6.04
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0094
config_converters.py in BSCW (Basic Support for Cooperative Work) 3.x and versions before 4.06 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name during filename conversion.... Read more
Affected Products : bscw- EPSS Score: %1.20
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1222
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.... Read more
Affected Products : plesk_server_administrator- EPSS Score: %2.26
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0129
efax 0.9 and earlier, when installed setuid root, allows local users to read arbitrary files via the -d option, which prints the contents of the file in a warning message.... Read more
Affected Products : efax- EPSS Score: %0.21
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0099
Buffer overflow in Michael Lamont Savant Web Server 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP request to the cgi-bin directory in which the CGI program name contains a large number of . (dot) characters.... Read more
Affected Products : savant_webserver- EPSS Score: %0.73
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0110
Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the passwords from the file.... Read more
Affected Products : miramail- EPSS Score: %0.20
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0131
ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attackers to read arbitrary files via a malicious web page cont... Read more
Affected Products : activepython- EPSS Score: %0.49
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0101
Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.... Read more
Affected Products : internet_explorer- EPSS Score: %10.62
- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2000-1210
Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.... Read more
Affected Products : tomcat- EPSS Score: %3.92
- Published: Mar. 22, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0061
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell... Read more
Affected Products : http_server- EPSS Score: %83.65
- Published: Mar. 21, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0076
Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.... Read more
- EPSS Score: %1.08
- Published: Mar. 19, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0058
Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 thr... Read more
- EPSS Score: %2.81
- Published: Mar. 15, 2002
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2002-0070
Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.... Read more
- EPSS Score: %26.11
- Published: Mar. 15, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0092
CVS before 1.10.8 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (server crash) via the diff capability.... Read more
Affected Products : cvs- EPSS Score: %1.27
- Published: Mar. 15, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0164
Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges.... Read more
- EPSS Score: %0.08
- Published: Mar. 15, 2002
- Modified: Apr. 03, 2025