Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 329 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2002-1375 | The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response. | EXPLOIT ✓HIGH 7.5EPSS 23.5% | 23 December 2002 |
| CVE-2002-1374 | The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first… | EXPLOIT ✓HIGH 7.5EPSS 20.5% | 23 December 2002 |
| CVE-2002-1361 | overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to execute arbitrary code via a POST request with shell metacharacters in the email parameter. | EXPLOIT ✓HIGH 10.0EPSS 11.9% | 23 December 2002 |
| CVE-2002-1359 | Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH… | EXPLOIT ×2 ✓HIGH 10.0EPSS 80.2% | 23 December 2002 |
| CVE-2002-1325 | Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability." | MEDIUM 5.0EPSS 13.9% | 23 December 2002 |
| CVE-2002-1260 | The Java Database Connectivity (JDBC) APIs in Microsoft Virtual Machine (VM) 5.0.3805 and earlier allow remote attackers to bypass security checks and access database contents via an untrusted Java applet. | HIGH 7.5EPSS 15.5% | 23 December 2002 |
| CVE-2002-1258 | Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in… | MEDIUM 5.0EPSS 15.3% | 23 December 2002 |
| CVE-2002-1257 | Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to execute arbitrary code by including a Java applet that invokes COM (Component Object Model) objects in a web site or an HTML mail. | HIGH 10.0EPSS 15.3% | 23 December 2002 |
| CVE-2002-1643 | Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two… | EXPLOIT ×3 ✓HIGH 7.5EPSS 74.7% | 19 December 2002 |
| CVE-2002-1340 | The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception. | MEDIUM 5.0EPSS 12.0% | 18 December 2002 |
| CVE-2002-1339 | The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files. | MEDIUM 5.0EPSS 12.0% | 18 December 2002 |
| CVE-2002-1338 | The Load method in the Chart component of Office Web Components (OWC) 9 and 10 generates an exception when a specified file does not exist, which allows remote attackers to determine the existence of local files. | MEDIUM 5.0EPSS 23.4% | 18 December 2002 |
| CVE-2002-1262 | Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files. | HIGH 7.5EPSS 12.0% | 18 December 2002 |
| CVE-2002-1255 | Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook… | MEDIUM 5.0EPSS 14.0% | 18 December 2002 |
| CVE-2002-1318 | Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a… | HIGH 10.0EPSS 51.9% | 11 December 2002 |
| CVE-2002-1317 | Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query. | EXPLOIT ✓HIGH 7.5EPSS 24.0% | 11 December 2002 |
| CVE-2002-1254 | Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via… | EXPLOIT ✓HIGH 7.5EPSS 53.5% | 11 December 2002 |
| CVE-2002-1188 | Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks,… | MEDIUM 6.4EPSS 12.3% | 11 December 2002 |
| CVE-2002-1187 | Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting,"… | EXPLOIT ✓MEDIUM 6.8EPSS 15.0% | 11 December 2002 |
| CVE-2002-1186 | Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that… | MEDIUM 5.0EPSS 19.1% | 11 December 2002 |
| CVE-2002-1185 | Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during… | MEDIUM 5.0EPSS 21.3% | 11 December 2002 |
| CVE-2002-1183 | Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862). | EXPLOIT ✓HIGH 7.5EPSS 19.3% | 11 December 2002 |
| CVE-2002-1295 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private… | HIGH 7.5EPSS 15.4% | 29 November 2002 |
| CVE-2002-1294 | The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other… | HIGH 7.5EPSS 14.7% | 29 November 2002 |
| CVE-2002-1293 | The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method. | HIGH 7.5EPSS 15.4% | 29 November 2002 |
| CVE-2002-1292 | The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended… | HIGH 7.5EPSS 22.4% | 29 November 2002 |
| CVE-2002-1291 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL. | MEDIUM 5.0EPSS 18.4% | 29 November 2002 |
| CVE-2002-1290 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class. | MEDIUM 6.4EPSS 14.3% | 29 November 2002 |
| CVE-2002-1289 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an… | HIGH 7.5EPSS 16.3% | 29 November 2002 |
| CVE-2002-1288 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call. | MEDIUM 5.0EPSS 17.4% | 29 November 2002 |
| CVE-2002-1287 | Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass. | MEDIUM 5.0EPSS 20.2% | 29 November 2002 |
| CVE-2002-1286 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an… | HIGH 7.5EPSS 20.5% | 29 November 2002 |
| CVE-2002-1219 | Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR). | HIGH 7.5EPSS 12.3% | 29 November 2002 |
| CVE-2002-1142 | Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data… | EXPLOIT ✓HIGH 7.5EPSS 76.0% | 29 November 2002 |
| CVE-2002-1182 | IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned. | MEDIUM 5.0EPSS 36.1% | 12 November 2002 |
| CVE-2002-1181 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the… | MEDIUM 6.8EPSS 39.4% | 12 November 2002 |
| CVE-2002-0869 | Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka… | HIGH 7.5EPSS 23.6% | 12 November 2002 |
| CVE-2002-1235 | The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before… | HIGH 10.0EPSS 15.1% | 4 November 2002 |
| CVE-2002-1209 | Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request. | EXPLOIT ✓MEDIUM 5.0EPSS 12.9% | 4 November 2002 |
| CVE-2002-0386 | The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request… | EXPLOIT ✓MEDIUM 5.0EPSS 22.0% | 4 November 2002 |
| CVE-2002-1217 | Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the… | EXPLOIT ✓HIGH 7.5EPSS 49.8% | 28 October 2002 |
| CVE-2002-1214 | Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data. | HIGH 7.5EPSS 50.8% | 28 October 2002 |
| CVE-2002-1179 | Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or… | EXPLOIT ✓HIGH 7.5EPSS 22.1% | 28 October 2002 |
| CVE-2001-1451 | Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT… | MEDIUM 5.0EPSS 27.9% | 22 October 2002 |
| CVE-2002-1156 | Apache 2.0.42 allows remote attackers to view the source code of a CGI script via a POST request to a directory with both WebDAV and CGI enabled. | MEDIUM 5.0EPSS 14.9% | 11 October 2002 |
| CVE-2002-1148 | The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet. | EXPLOIT ✓MEDIUM 5.0EPSS 18.6% | 11 October 2002 |
| CVE-2002-1141 | An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka… | MEDIUM 5.0EPSS 13.9% | 11 October 2002 |
| CVE-2002-1140 | The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size… | MEDIUM 5.0EPSS 13.9% | 11 October 2002 |
| CVE-2002-0867 | Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw." | MEDIUM 5.0EPSS 27.3% | 11 October 2002 |
| CVE-2002-0866 | Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc… | EXPLOIT ✓HIGH 7.5EPSS 41.4% | 11 October 2002 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.