Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2003-0007
Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outloo…
Outlook
Mitigation only
HIGH 10.0
CVE-2002-1918EPSS 16%
Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown …
Data Access Components
No fix yet
HIGH 7.8
CVE-2002-1844
Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users t…
Windows Media Player
Mitigation only
HIGH 7.5
CVE-2002-1745EPSS 18%
Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions con…
Internet Information Services
Mitigation only
HIGH 7.5
CVE-2002-1847EPSS 34%
Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a lo…
Windows Media Player
No fix yet
HIGH 7.5
CVE-2002-1872EPSS 6%
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff a…
Sql Server
Mitigation only
HIGH 7.5
CVE-2002-2101EPSS 11%
Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:…
Outlook
Mitigation only
HIGH 7.2
CVE-2002-1933
The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could …
Windows 2000 Terminal Services
Mitigation only
MEDIUM 6.4
CVE-2002-2125EPSS 8%
Internet Explorer 6.0 does not warn users when an expired certificate authority (CA) certificate is submitted to the user and a newer CA certificate …
Ie
Mitigation only
MEDIUM 6.4
CVE-2002-2311EPSS 10%
Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to…
Internet Explorer
No fix yet
MEDIUM 6.4
CVE-2002-2380EPSS 11%
NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented u…
Network Firmware
Mitigation only
MEDIUM 5.0
CVE-2002-1694EPSS 13%
Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attac…
Internet Information Server
Mitigation only
MEDIUM 5.0
CVE-2002-1695EPSS 14%
Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the…
Internet Information Server
Mitigation only
MEDIUM 5.0
CVE-2002-1698EPSS 16%
Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) …
Msn Messenger
Mitigation only
MEDIUM 5.0
CVE-2002-1714EPSS 19%
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the D…
Ie
Mitigation only
MEDIUM 5.0
CVE-2002-1716EPSS 14%
The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs …
Office
Mitigation only
MEDIUM 5.0
CVE-2002-1717EPSS 16%
Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /…
Internet Information Services
Mitigation only
MEDIUM 5.0
CVE-2002-1718EPSS 14%
Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claim…
Internet Information Services
Mitigation only
MEDIUM 5.0
CVE-2002-1744EPSS 65%
Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arb…
Internet Information Services
No fix yet
MEDIUM 5.0
CVE-2002-1762EPSS 16%
Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plainte…
Baseline Security Analyzer
No fix yet
MEDIUM 5.0
CVE-2002-1824
Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the …
Ie
Mitigation only
MEDIUM 5.0
CVE-2002-1831EPSS 22%
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-…
Msn Messenger
No fix yet
MEDIUM 5.0
CVE-2002-1873EPSS 14%
Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memor…
Exchange Server
Mitigation only
MEDIUM 5.0
CVE-2002-1981
Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo s…
Sql Server
Mitigation only
MEDIUM 5.0
CVE-2002-2081EPSS 14%
cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a lon…
Site Server
Mitigation only
MEDIUM 5.0
CVE-2002-2100EPSS 11%
Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an …
Outlook
Mitigation only
HIGH 10.0
CVE-2002-1257EPSS 15%
Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that i…
Windows 2000
Mitigation only
HIGH 7.5
CVE-2002-1260EPSS 16%
The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks an…
Windows 2000
Mitigation only
MEDIUM 5.0
CVE-2002-1256EPSS 5%
The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digita…
Windows 2000
Mitigation only
MEDIUM 5.0
CVE-2002-1258EPSS 15%
Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow …
Windows 2000
Mitigation only