Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
396,088 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 330 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2002-0865 | A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet,… | HIGH 7.5EPSS 19.8% | 11 October 2002 |
| CVE-2002-0864 | The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of… | MEDIUM 5.0EPSS 16.0% | 11 October 2002 |
| CVE-2002-0863 | Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka… | MEDIUM 5.0EPSS 22.0% | 11 October 2002 |
| CVE-2002-0843 | Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response. | HIGH 7.5EPSS 21.4% | 11 October 2002 |
| CVE-2002-0840 | Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page… | EXPLOIT ✓MEDIUM 6.8EPSS 95.1% | 11 October 2002 |
| CVE-2002-0694 | The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files… | HIGH 7.5EPSS 13.7% | 10 October 2002 |
| CVE-2002-0693 | Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long… | EXPLOIT ✓HIGH 7.5EPSS 31.3% | 10 October 2002 |
| CVE-2002-0692 | Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file… | HIGH 7.5EPSS 18.0% | 10 October 2002 |
| CVE-2002-0370 | Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! | HIGH 7.5EPSS 43.3% | 10 October 2002 |
| CVE-2002-1131 | Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as other web users via (1) addressbook.php, (2) options.php, (3) search.php, or (4) help.php. | EXPLOIT ✓HIGH 7.5EPSS 25.6% | 4 October 2002 |
| CVE-2002-1077 | IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field. | EXPLOIT ✓MEDIUM 5.0EPSS 10.7% | 4 October 2002 |
| CVE-2002-1076 | Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0. | EXPLOIT ✓HIGH 7.5EPSS 13.8% | 4 October 2002 |
| CVE-2002-1059 | Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string. | EXPLOIT ×3 ✓HIGH 7.5EPSS 60.3% | 4 October 2002 |
| CVE-2002-1048 | HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0. | EXPLOIT ✓HIGH 7.5EPSS 13.5% | 4 October 2002 |
| CVE-2002-0965 | Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log… | EXPLOIT ✓HIGH 7.5EPSS 69.8% | 4 October 2002 |
| CVE-2002-0936 | The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null). | EXPLOIT ✓MEDIUM 5.0EPSS 27.3% | 4 October 2002 |
| CVE-2002-0862 | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for… | EXPLOIT ✓MEDIUM 6.8EPSS 15.8% | 4 October 2002 |
| CVE-2002-0696 | Microsoft Visual FoxPro 6.0 does not register its associated files with Internet Explorer, which allows remote attackers to execute Visual FoxPro applications without warning via HTML that references specially-crafted filenames. | HIGH 7.5EPSS 11.7% | 4 October 2002 |
| CVE-2002-1123 | Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow. | EXPLOIT ×2 ✓HIGH 7.5EPSS 77.7% | 24 September 2002 |
| CVE-2002-1120 | Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | EXPLOIT ×4 ✓HIGH 7.5EPSS 66.6% | 24 September 2002 |
| CVE-2002-0980 | The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error… | EXPLOIT ✓HIGH 7.5EPSS 26.7% | 24 September 2002 |
| CVE-2002-0977 | Buffer overflow in Microsoft File Transfer Manager (FTM) ActiveX control before 4.0 allows remote attackers to execute arbitrary code via a long TS value. | HIGH 7.5EPSS 10.9% | 24 September 2002 |
| CVE-2002-0976 | Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the… | EXPLOIT ✓MEDIUM 6.4EPSS 14.3% | 24 September 2002 |
| CVE-2002-0975 | Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter. | HIGH 7.5EPSS 12.8% | 24 September 2002 |
| CVE-2002-0974 | Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm. | EXPLOIT ✓MEDIUM 5.0EPSS 15.0% | 24 September 2002 |
| CVE-2002-0861 | Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object. | HIGH 7.5EPSS 15.8% | 24 September 2002 |
| CVE-2002-0860 | The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file. | MEDIUM 5.0EPSS 18.8% | 24 September 2002 |
| CVE-2002-0727 | The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method. | HIGH 7.5EPSS 18.8% | 24 September 2002 |
| CVE-2002-0726 | Buffer overflow in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to execute arbitrary code via a long server name field. | HIGH 7.5EPSS 17.4% | 24 September 2002 |
| CVE-2002-0724 | Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2)… | EXPLOIT ×2 ✓HIGH 7.5EPSS 25.7% | 24 September 2002 |
| CVE-2002-0723 | Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object… | EXPLOIT ✓HIGH 7.5EPSS 15.0% | 24 September 2002 |
| CVE-2002-0722 | Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing." | HIGH 7.5EPSS 13.1% | 24 September 2002 |
| CVE-2002-0691 | Microsoft Internet Explorer 5.01 and 5.5 allows remote attackers to execute scripts in the Local Computer zone via a URL that references a local HTML resource file, a variant of "Cross-Site Scripting in Local HTML Resource" as identified by CAN-2002-0189. | HIGH 7.5EPSS 13.8% | 24 September 2002 |
| CVE-2002-0648 | The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file. | EXPLOIT ✓MEDIUM 5.0EPSS 48.4% | 24 September 2002 |
| CVE-2002-0647 | Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control". | EXPLOIT ✓HIGH 7.5EPSS 23.3% | 24 September 2002 |
| CVE-2002-0859 | Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code. | EXPLOIT ✓HIGH 7.5EPSS 26.2% | 5 September 2002 |
| CVE-2002-0857 | Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the… | HIGH 7.5EPSS 13.8% | 5 September 2002 |
| CVE-2002-0721 | Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator… | EXPLOIT ✓HIGH 10.0EPSS 46.3% | 5 September 2002 |
| CVE-2002-0679 | Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure. | HIGH 10.0EPSS 23.3% | 5 September 2002 |
| CVE-2002-0654 | Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that… | EXPLOIT ✓MEDIUM 5.0EPSS 58.7% | 5 September 2002 |
| CVE-2002-1605 | Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET environment variable to (1) dxpause, (2) dxconsole, or (3) dtsession. | EXPLOIT ✓HIGH 7.5EPSS 13.3% | 2 September 2002 |
| CVE-2002-1604 | Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9)… | HIGH 7.5EPSS 15.0% | 2 September 2002 |
| CVE-2002-1444 | The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an… | EXPLOIT ✓LOW 2.6EPSS 13.5% | 15 August 2002 |
| CVE-2002-0845 | Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding. | HIGH 7.5EPSS 13.3% | 12 August 2002 |
| CVE-2002-0826 | Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary code via a long SITE CPWD command. | HIGH 7.5EPSS 12.2% | 12 August 2002 |
| CVE-2002-0823 | Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HTML Help ActiveX control (HHCtrl.ocx) with a long pathname in the Item parameter. | EXPLOIT ✓HIGH 7.5EPSS 26.2% | 12 August 2002 |
| CVE-2002-0814 | Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users to execute arbitrary code via a long GLOBAL argument. | EXPLOIT ✓HIGH 7.5EPSS 13.7% | 12 August 2002 |
| CVE-2002-0799 | Buffer overflow in YoungZSoft CMailServer 3.30 allows remote attackers to execute arbitrary code via a long USER argument. | EXPLOIT ×2 ✓HIGH 7.5EPSS 13.9% | 12 August 2002 |
| CVE-2002-0777 | Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter. | HIGH 10.0EPSS 10.3% | 12 August 2002 |
| CVE-2002-0764 | Phorum 3.3.2a allows remote attackers to execute arbitrary commands via an HTTP request to (1) plugin.php, (2) admin.php, or (3) del.php that modifies the PHORUM[settings_dir] variable to point to a directory that contains a PHP file with the commands. | EXPLOIT ✓HIGH 7.5EPSS 38.3% | 12 August 2002 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.