Latest CVE Feed
-
7.2
HIGHCVE-2002-0246
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message catalogs containing format strings from setuid programs suc... Read more
Affected Products : unixware- EPSS Score: %0.24
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0267
preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin command, which causes the Status line to be entered into ... Read more
Affected Products : sips- EPSS Score: %1.19
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0252
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header.... Read more
Affected Products : quicktime- EPSS Score: %4.58
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2002-0271
Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.... Read more
Affected Products : gnat_pro_native- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0259
InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.... Read more
Affected Products : miniportal- EPSS Score: %0.07
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0239
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.... Read more
Affected Products : hanterm- EPSS Score: %0.27
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0260
Buffer overflow in InstantServers MiniPortal 1.1.5 and earlier allows remote attackers to execute arbitrary code via a long login name, which is not properly handled by the logging utility.... Read more
Affected Products : miniportal- EPSS Score: %3.31
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0263
Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, or (3) ezadmin.cgi.... Read more
Affected Products : ezboard_2000- EPSS Score: %21.10
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0188
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system f... Read more
Affected Products : internet_explorer- EPSS Score: %20.21
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0261
Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.... Read more
Affected Products : miniportal- EPSS Score: %3.16
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0033
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.... Read more
- EPSS Score: %55.47
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0237
Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a flood of large ICMP ping... Read more
- EPSS Score: %3.24
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0251
Buffer overflow in licq 1.0.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string of format string characters such as "%d".... Read more
Affected Products : licq- EPSS Score: %5.48
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0264
PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.... Read more
Affected Products : powerftp- EPSS Score: %0.53
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0233
Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.... Read more
Affected Products : eshare_expressions- EPSS Score: %1.14
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0375
Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter.... Read more
Affected Products : sgdynamo- EPSS Score: %3.83
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0245
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any reque... Read more
Affected Products : domino- EPSS Score: %0.74
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0232
Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.... Read more
Affected Products : multi_router_traffic_grapher_cgi- EPSS Score: %1.61
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0241
NDSAuth.DLL in Cisco Secure Authentication Control Server (ACS) 3.0.1 does not check the Expired or Disabled state of users in the Novell Directory Services (NDS), which could allow those users to authenticate to the server.... Read more
Affected Products : secure_access_control_server- EPSS Score: %0.19
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2002-0265
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows local users to gain privileges by modifying the file.... Read more
Affected Products : sawmill- EPSS Score: %0.21
- Published: May. 29, 2002
- Modified: Apr. 03, 2025