Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2002-0670

    The web interface for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 uses Base64 encoded usernames and passwords for HTTP basic authentication, which allows remote attackers to steal and easily decode the passwords via sniffing.... Read more

    Affected Products : xpressa
    • EPSS Score: %1.26
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0686

    Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter.... Read more

    Affected Products : iplanet_web_server
    • EPSS Score: %4.68
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0682

    Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.... Read more

    Affected Products : tomcat
    • EPSS Score: %66.60
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-0673

    The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In to gain remote access and perfo... Read more

    Affected Products : xpressa
    • EPSS Score: %0.16
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0667

    Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 has a default null administrator password, which could allow remote attackers to gain access to the phone.... Read more

    Affected Products : xpressa
    • EPSS Score: %2.20
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0641

    Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT que... Read more

    Affected Products : sql_server sql_server msde
    • EPSS Score: %16.41
    • Published: Jul. 23, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0665

    Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra slash (/) in the URL.... Read more

    Affected Products : jrun
    • EPSS Score: %3.54
    • Published: Jul. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0637

    InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers that violate RFC specifications by having (or missing) space characters in unexpected places (aka "space gap"), such as (1) Content-Typ... Read more

    Affected Products : interscan_viruswall
    • EPSS Score: %3.82
    • Published: Jul. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2002-0653

    Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apache module 2.8.9 and earlier, allows local users to execute arbitrary code as the Apache server user via .htaccess files with long entrie... Read more

    Affected Products : mod_ssl
    • EPSS Score: %0.46
    • Published: Jul. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0676

    SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and s... Read more

    Affected Products : mac_os_x
    • EPSS Score: %6.42
    • Published: Jul. 11, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1448

    An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.... Read more

    Affected Products : cajun_m770-atm cajun_p130 cajun_p330
    • EPSS Score: %1.40
    • Published: Jul. 08, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0556

    Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.... Read more

    Affected Products : quik-serv_webserver
    • EPSS Score: %0.26
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0557

    Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrec... Read more

    Affected Products : openbsd
    • EPSS Score: %0.53
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0622

    The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".... Read more

    Affected Products : commerce_server
    • EPSS Score: %10.27
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0652

    xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().... Read more

    Affected Products : irix
    • EPSS Score: %6.84
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0541

    Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HT... Read more

    Affected Products : tivoli_storage_manager
    • EPSS Score: %4.11
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0549

    Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users.... Read more

    Affected Products : anthill
    • EPSS Score: %0.85
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0559

    Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Locati... Read more

    • EPSS Score: %26.41
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0566

    PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.... Read more

    • EPSS Score: %1.55
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0615

    The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation".... Read more

    Affected Products : office excel
    • EPSS Score: %11.40
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 292758 Results