Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 328 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2002-2164 | Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link. | EXPLOIT ✓MEDIUM 5.0EPSS 21.9% | 31 December 2002 |
| CVE-2002-2117 | Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP). | MEDIUM 5.0EPSS 11.8% | 31 December 2002 |
| CVE-2002-2101 | Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag. | HIGH 7.5EPSS 11.1% | 31 December 2002 |
| CVE-2002-2100 | Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content. | MEDIUM 5.0EPSS 11.4% | 31 December 2002 |
| CVE-2002-2081 | cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp. | MEDIUM 5.0EPSS 13.9% | 31 December 2002 |
| CVE-2002-2077 | The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session. | MEDIUM 5.0EPSS 15.9% | 31 December 2002 |
| CVE-2002-2073 | Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to… | EXPLOIT ✓MEDIUM 4.3EPSS 12.9% | 31 December 2002 |
| CVE-2002-2062 | Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web… | EXPLOIT ✓MEDIUM 4.3EPSS 13.3% | 31 December 2002 |
| CVE-2002-2031 | Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existence of arbitrary files via a script tag with a src parameter that references a non-JavaScript file, then using the onError event… | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 20.5% | 31 December 2002 |
| CVE-2002-2029 | PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string. | EXPLOIT ✓HIGH 7.5EPSS 23.1% | 31 December 2002 |
| CVE-2002-2007 | The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2)… | EXPLOIT ×3 ✓MEDIUM 5.0EPSS 41.4% | 31 December 2002 |
| CVE-2002-2006 | The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets. | EXPLOIT ✓MEDIUM 5.0EPSS 30.7% | 31 December 2002 |
| CVE-2002-1993 | webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter. | EXPLOIT ✓HIGH 10.0EPSS 11.9% | 31 December 2002 |
| CVE-2002-1973 | Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote… | EXPLOIT ✓HIGH 7.5EPSS 40.0% | 31 December 2002 |
| CVE-2002-1954 | Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php. | EXPLOIT ✓MEDIUM 4.3EPSS 11.9% | 31 December 2002 |
| CVE-2002-1932 | Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users… | HIGH 7.5EPSS 12.8% | 31 December 2002 |
| CVE-2002-1918 | Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. | HIGH 10.0EPSS 16.4% | 31 December 2002 |
| CVE-2002-1908 | Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters. | MEDIUM 5.0EPSS 13.7% | 31 December 2002 |
| CVE-2002-1873 | Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls. | MEDIUM 5.0EPSS 13.6% | 31 December 2002 |
| CVE-2002-1864 | Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request. | MEDIUM 5.0EPSS 17.8% | 31 December 2002 |
| CVE-2002-1850 | mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock… | EXPLOIT ✓HIGH 7.5EPSS 17.4% | 31 December 2002 |
| CVE-2002-1847 | Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. | EXPLOIT ✓HIGH 7.5EPSS 33.6% | 31 December 2002 |
| CVE-2002-1831 | Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field. | EXPLOIT ✓MEDIUM 5.0EPSS 22.3% | 31 December 2002 |
| CVE-2002-1823 | Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP request. | EXPLOIT ✓HIGH 7.5EPSS 10.2% | 31 December 2002 |
| CVE-2002-1809 | The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers to gain unauthorized root access to the MySQL database. | EXPLOIT ✓HIGH 7.5EPSS 16.1% | 31 December 2002 |
| CVE-2002-1795 | Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | MEDIUM 4.3EPSS 16.8% | 31 December 2002 |
| CVE-2002-1790 | The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682. | EXPLOIT ✓MEDIUM 5.0EPSS 34.0% | 31 December 2002 |
| CVE-2002-1783 | CRLF injection vulnerability in PHP 4.2.1 through 4.2.3, when allow_url_fopen is enabled, allows remote attackers to modify HTTP headers for outgoing requests by causing CRLF sequences to be injected into arguments that are passed to the (1) fopen or… | MEDIUM 5.0EPSS 16.7% | 31 December 2002 |
| CVE-2002-1769 | Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "Log on locally" privilege. | HIGH 7.5EPSS 11.7% | 31 December 2002 |
| CVE-2002-1762 | Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious… | MEDIUM 5.0EPSS 15.9% | 31 December 2002 |
| CVE-2002-1753 | csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. | HIGH 7.5EPSS 32.2% | 31 December 2002 |
| CVE-2002-1745 | Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files. | HIGH 7.5EPSS 17.7% | 31 December 2002 |
| CVE-2002-1744 | Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot… | EXPLOIT ✓MEDIUM 5.0EPSS 65.2% | 31 December 2002 |
| CVE-2002-1718 | Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claimed using an HTTP request for colegal.htm that contains .. | MEDIUM 5.0EPSS 14.9% | 31 December 2002 |
| CVE-2002-1717 | Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /_vti_pvt/botinfs.cnf, (3) /_vti_pvt/bots.cnf, or (4) /_vti_pvt/linkinfo.cnf. | MEDIUM 5.0EPSS 16.5% | 31 December 2002 |
| CVE-2002-1716 | The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability. | MEDIUM 5.0EPSS 14.3% | 31 December 2002 |
| CVE-2002-1714 | Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion. | EXPLOIT ✓MEDIUM 5.0EPSS 19.4% | 31 December 2002 |
| CVE-2002-1712 | Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3. | EXPLOIT ×2 ✓MEDIUM 5.0EPSS 25.8% | 31 December 2002 |
| CVE-2002-1705 | Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight. | EXPLOIT ✓MEDIUM 5.0EPSS 17.6% | 31 December 2002 |
| CVE-2002-1700 | Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not… | EXPLOIT ✓MEDIUM 4.3EPSS 24.3% | 31 December 2002 |
| CVE-2002-1698 | Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header. | MEDIUM 5.0EPSS 15.5% | 31 December 2002 |
| CVE-2002-1695 | Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running. | MEDIUM 5.0EPSS 13.6% | 31 December 2002 |
| CVE-2002-1694 | Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running. | MEDIUM 5.0EPSS 13.0% | 31 December 2002 |
| CVE-2002-1688 | The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when… | EXPLOIT ✓MEDIUM 5.0EPSS 17.5% | 31 December 2002 |
| CVE-2002-1671 | Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of the clipboard via the getData method of the clipboardData object. | MEDIUM 5.0EPSS 12.1% | 31 December 2002 |
| CVE-2002-1660 | calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter. | EXPLOIT ✓HIGH 7.5EPSS 11.1% | 31 December 2002 |
| CVE-2002-1634 | Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndsobj.nlm, (2) allfield.jse, (3) websinfo.bas, (4) ndslogin.pl, (5) volscgi.pl, (6) lancgi.pl, (7) test.jse, or (8) env.pl. | EXPLOIT ✓MEDIUM 5.0EPSS 17.0% | 31 December 2002 |
| CVE-2002-1623 | The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by… | MEDIUM 5.0EPSS 48.6% | 31 December 2002 |
| CVE-2002-1368 | Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative… | EXPLOIT ✓HIGH 7.5EPSS 15.5% | 26 December 2002 |
| CVE-2002-1327 | Buffer overflow in the Windows Shell function in Microsoft Windows XP allows remote attackers to execute arbitrary code via an .MP3 or .WMA audio file with a corrupt custom attribute, aka "Unchecked Buffer in Windows Shell Could Enable System Compromise." | HIGH 7.5EPSS 23.4% | 26 December 2002 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.