Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 2.1

    LOW
    CVE-2002-0294

    Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.... Read more

    Affected Products : omnipcx
    • EPSS Score: %0.08
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0301

    Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.... Read more

    Affected Products : nfuse
    • EPSS Score: %0.62
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0289

    Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.... Read more

    Affected Products : phusion_webserver
    • EPSS Score: %4.31
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0278

    Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.... Read more

    Affected Products : mailman_free
    • EPSS Score: %1.96
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0309

    SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an SMTP protocol exchange when NAT translation is made to an address other than the firewall, which could allow remote attackers to deter... Read more

    Affected Products : enterprise_firewall
    • EPSS Score: %0.86
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0308

    admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.... Read more

    Affected Products : admentor
    • EPSS Score: %0.43
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2002-0292

    Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.... Read more

    Affected Products : slashcode
    • EPSS Score: %0.44
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0306

    ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.... Read more

    Affected Products : avengers_news_system
    • EPSS Score: %1.00
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0288

    Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.... Read more

    Affected Products : phusion_webserver
    • EPSS Score: %2.22
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-0303

    GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.... Read more

    Affected Products : groupwise
    • EPSS Score: %0.04
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0275

    Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.... Read more

    Affected Products : falcon_web_server
    • EPSS Score: %0.53
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 6.2

    MEDIUM
    CVE-2002-0293

    FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.... Read more

    Affected Products : omnipcx
    • EPSS Score: %0.07
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0283

    Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data.... Read more

    Affected Products : windows_xp
    • EPSS Score: %3.44
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0290

    Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.... Read more

    Affected Products : webnews
    • EPSS Score: %3.74
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0374

    Format string vulnerability in the logging function for the pam_ldap PAM LDAP module before version 144 allows attackers to execute arbitrary code via format strings in the configuration file name.... Read more

    Affected Products : linux pam_ldap
    • EPSS Score: %1.73
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0248

    wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.... Read more

    Affected Products : wmtv
    • EPSS Score: %0.15
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0193

    Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system f... Read more

    Affected Products : internet_explorer
    • EPSS Score: %45.78
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0178

    uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands.... Read more

    Affected Products : linux sharutils
    • EPSS Score: %0.13
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0244

    Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.... Read more

    Affected Products : atheos
    • EPSS Score: %1.92
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0236

    Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.... Read more

    • EPSS Score: %7.28
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 292759 Results