Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2002-0314

    fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.... Read more

    Affected Products : grokster kazaa morpheus
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2001-1300

    Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.... Read more

    Affected Products : dynu_ftp_server
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0312

    Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.... Read more

    Affected Products : essentia_web_server
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2002-0367

    smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as dem... Read more

    Affected Products : windows_2000 windows_nt
    • Actively Exploited
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0344

    Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.... Read more

    Affected Products : liveupdate
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0327

    Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.... Read more

    Affected Products : term
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0351

    Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.... Read more

    Affected Products : cfs
    • Published: Jun. 25, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0368

    The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."... Read more

    Affected Products : exchange_server
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0593

    Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.... Read more

    Affected Products : mozilla navigator communicator
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0605

    Buffer overflow in Flash OCX for Macromedia Flash 6 revision 23 (6,0,23,0) allows remote attackers to execute arbitrary code via a long movie parameter.... Read more

    Affected Products : flash_player
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0597

    LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.... Read more

    Affected Products : windows_2000
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0604

    Snapgear Lite+ firewall 1.5.3 and 1.5.4 allows remote attackers to cause a denial of service (crash) via a large number of packets with malformed IP options.... Read more

    Affected Products : snapgear_lite\+_firewall
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0588

    PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.... Read more

    Affected Products : pvote
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-0577

    Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.... Read more

    Affected Products : hp-ux
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0582

    WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote attackers to read the reports by accessing the directory.... Read more

    Affected Products : xpede
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0592

    AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user.... Read more

    Affected Products : instant_messenger
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0380

    Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS packet.... Read more

    Affected Products : linux tcpdump
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0581

    WorkforceROI Xpede 4.1 allows remote attackers to execute arbitrary SQL commands and read, modify, or steal credentials from the database via the Qry parameter in the sprc.asp script.... Read more

    Affected Products : xpede
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0579

    WorkforceROI Xpede 4.1 allows remote attackers to gain privileges as an Xpede administrator via a direct HTTP request to the /admin/adminproc.asp script, which does not prompt for a password.... Read more

    Affected Products : xpede
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0584

    WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for each new timesheet.... Read more

    Affected Products : xpede
    • Published: Jun. 18, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 292803 Results