Latest CVE Feed
-
5.0
MEDIUMCVE-2001-1186
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.... Read more
Affected Products : internet_information_services- EPSS Score: %32.41
- Published: Dec. 11, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0890
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.... Read more
- EPSS Score: %0.09
- Published: Dec. 11, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1187
csvform.pl 0.1 allows remote attackers to execute arbitrary commands via metacharacters in the file parameter.... Read more
- EPSS Score: %3.12
- Published: Dec. 11, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1191
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.... Read more
Affected Products : tivoli_secureway_policy_director- EPSS Score: %0.61
- Published: Dec. 11, 2001
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2001-1185
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.... Read more
Affected Products : freebsd- EPSS Score: %0.13
- Published: Dec. 10, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0953
Kebi WebMail allows remote attackers to access the administrator menu and gain privileges via the /a/ hidden directory, which is installed under the web document root.... Read more
Affected Products : kebi_community- EPSS Score: %1.10
- Published: Dec. 08, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1184
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that ... Read more
Affected Products : winsock_rshd_nt- EPSS Score: %19.48
- Published: Dec. 08, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0952
THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via packets to UDP port 7755.... Read more
Affected Products : red_faction- EPSS Score: %4.72
- Published: Dec. 07, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0951
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dot characters.... Read more
Affected Products : windows_2000- EPSS Score: %56.34
- Published: Dec. 07, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0954
Lotus Domino 5.0.5 and 5.0.8, and possibly other versions, allows remote attackers to cause a denial of service (block access to databases that have not been previously accessed) via a URL that includes the . (dot) directory.... Read more
Affected Products : domino- EPSS Score: %0.91
- Published: Dec. 07, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0862
Cisco 12000 with IOS 12.0 and line cards based on Engine 2 does not block non-initial packet fragments, which allows remote attackers to bypass the ACL.... Read more
Affected Products : 12000_router- EPSS Score: %0.45
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-0722
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."... Read more
Affected Products : internet_explorer- EPSS Score: %45.91
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0721
Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.... Read more
- EPSS Score: %19.07
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0826
Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.... Read more
Affected Products : cesarftp- EPSS Score: %1.15
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2001-0829
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.... Read more
Affected Products : tomcat- EPSS Score: %0.73
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0838
Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers to execute arbitrary code via format string specifiers in the -soa command.... Read more
Affected Products : rwhoisd- EPSS Score: %4.45
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0849
viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget.... Read more
Affected Products : viralator- EPSS Score: %1.98
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0671
Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.... Read more
Affected Products : aix- EPSS Score: %5.64
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0804
Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files via a .. (dot dot) attack on the "next" parameter.... Read more
Affected Products : interactive_story- EPSS Score: %6.89
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0854
PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of ... Read more
Affected Products : php-nuke- EPSS Score: %0.02
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025