Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2002-1124

    Multiple buffer overflows in purity 1-16 allow local users to gain privileges and modify high scores tables.... Read more

    Affected Products : purity
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0975

    Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.... Read more

    Affected Products : directx_files_viewer_control
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0860

    The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.... Read more

    Affected Products : project office_web_components
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0987

    X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.... Read more

    Affected Products : unixware openunix
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0989

    The URL handler in the manual browser option for Gaim before 0.59.1 allows remote attackers to execute arbitrary script via shell metacharacters in a link.... Read more

    Affected Products : linux gaim
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0980

    The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error mes... Read more

    Affected Products : internet_explorer outlook_express
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0979

    The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code.... Read more

    Affected Products : virtual_machine
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0981

    Buffer overflow in ndcfg command for UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to execute arbitrary code via a long command line.... Read more

    Affected Products : unixware openunix
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-0972

    Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.... Read more

    Affected Products : postgresql
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0986

    The mail function in PHP 4.x to 4.2.2 does not filter ASCII control characters from its arguments, which could allow remote attackers to modify mail message content, including mail headers, and possibly use PHP as a "spam proxy."... Read more

    Affected Products : php
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-1121

    SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails... Read more

    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0985

    Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly ... Read more

    Affected Products : php openpkg
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2002-0973

    Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) ve... Read more

    Affected Products : freebsd
    • Published: Sep. 24, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-1615

    Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to execute arbitrary code via (1) msgchk or (2) .upd..loader.... Read more

    Affected Products : hp-ux tru64
    • Published: Sep. 13, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-1612

    Buffer overflow in mailcv in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.... Read more

    Affected Products : hp-ux tru64
    • Published: Sep. 13, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-1613

    Buffer overflow in ps in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows local users to gain privileges.... Read more

    Affected Products : hp-ux tru64
    • Published: Sep. 10, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-1614

    Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.... Read more

    Affected Products : hp-ux tru64
    • Published: Sep. 09, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0093

    Buffer overflow in ipcs for HP Tru64 UNIX 4.0f through 5.1a may allow attackers to execute arbitrary code, a different vulnerability than CVE-2001-0423.... Read more

    Affected Products : tru64
    • Published: Sep. 05, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0855

    Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscription options in the (1) adminpw or (2) info parameters to the ml-name feature.... Read more

    Affected Products : mailman
    • Published: Sep. 05, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0721

    Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator pri... Read more

    Affected Products : sql_server sql_server data_engine
    • Published: Sep. 05, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 294860 Results