Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2002-1448

    An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.... Read more

    Affected Products : cajun_m770-atm cajun_p130 cajun_p330
    • Published: Jul. 08, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0556

    Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.... Read more

    Affected Products : quik-serv_webserver
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0652

    xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().... Read more

    Affected Products : irix
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0557

    Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrec... Read more

    Affected Products : openbsd
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0622

    The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".... Read more

    Affected Products : commerce_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0541

    Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HT... Read more

    Affected Products : tivoli_storage_manager
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0549

    Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users.... Read more

    Affected Products : anthill
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0187

    Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."... Read more

    Affected Products : sql_server sql_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0392

    Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.... Read more

    Affected Products : debian_linux http_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0631

    Unknown vulnerability in nveventd in NetVisualyzer on SGI IRIX 6.5 through 6.5.16 allows local users to write arbitrary files and gain root privileges.... Read more

    Affected Products : irix
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0537

    The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.... Read more

    Affected Products : sws
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0372

    Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored... Read more

    Affected Products : windows_media_player
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0639

    Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.... Read more

    Affected Products : openssh
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0359

    xfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can mount or unmount xfs file systems, to gain root privileges.... Read more

    Affected Products : irix
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0371

    Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that ... Read more

    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0551

    Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar.... Read more

    Affected Products : dynamic_guestbook
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0558

    Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending in wildcard *.* characters.... Read more

    Affected Products : typsoft_ftp_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0620

    Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.... Read more

    Affected Products : commerce_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0651

    Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.... Read more

    Affected Products : bind
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0555

    IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.... Read more

    Affected Products : informix_web_datablade
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 294848 Results