Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2002-0554

    webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary files via a SQL injection attack in an HTTP request.... Read more

    Affected Products : informix_web_datablade
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0548

    Anthill allows remote attackers to bypass authentication and file bug reports by directly accessing the postbug.php program instead of enterbug.php.... Read more

    Affected Products : anthill
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0558

    Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending in wildcard *.* characters.... Read more

    Affected Products : typsoft_ftp_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0620

    Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.... Read more

    Affected Products : commerce_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0651

    Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.... Read more

    Affected Products : bind
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0555

    IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.... Read more

    Affected Products : informix_web_datablade
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0571

    Oracle Oracle9i database server 9.0.1.x allows local users to access restricted data via a SQL query using ANSI outer join syntax.... Read more

    Affected Products : database_server oracle9i
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0544

    Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.... Read more

    Affected Products : abyss_web_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0372

    Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored... Read more

    Affected Products : windows_media_player
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0552

    Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configurat... Read more

    Affected Products : melange_chat_system
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0539

    Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.... Read more

    Affected Products : puresecure
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2002-0570

    The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.... Read more

    Affected Products : linux_kernel linux
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0186

    Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."... Read more

    Affected Products : sql_server sql_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0564

    PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.... Read more

    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2002-0542

    mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.... Read more

    Affected Products : openbsd
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0546

    Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.... Read more

    Affected Products : winamp
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0652

    xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs().... Read more

    Affected Products : irix
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0566

    PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.... Read more

    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2002-0536

    PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.... Read more

    Affected Products : phpgroupware
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2002-0543

    Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.... Read more

    Affected Products : abyss_web_server
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 294848 Results