Latest CVE Feed
-
5.0
MEDIUMCVE-2001-0716
Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.... Read more
Affected Products : metaframe- EPSS Score: %1.11
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0845
Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.... Read more
- EPSS Score: %0.07
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2001-1247
PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploading a PHP script that uses the error_log function to access the files.... Read more
Affected Products : php- EPSS Score: %0.65
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0860
Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Addre... Read more
- EPSS Score: %9.10
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0844
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.... Read more
- EPSS Score: %2.31
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0832
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the O... Read more
Affected Products : database_server- EPSS Score: %0.24
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0801
lpstat in IRIX 6.5.13f and earlier allows local users to gain root privileges by specifying a Trojan Horse nettype shared library.... Read more
Affected Products : irix- EPSS Score: %0.05
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0840
Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.... Read more
Affected Products : insight_manager_xe- EPSS Score: %12.53
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0837
DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.... Read more
Affected Products : pc-to-phone- EPSS Score: %0.07
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0824
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javasc... Read more
Affected Products : websphere_application_server- EPSS Score: %0.84
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0858
Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges.... Read more
- EPSS Score: %0.08
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0719
Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.... Read more
Affected Products : windows_media_player- EPSS Score: %17.15
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0833
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."... Read more
Affected Products : database_server- EPSS Score: %0.45
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0827
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.... Read more
Affected Products : ceberus_ftp_server- EPSS Score: %0.96
- Published: Dec. 06, 2001
- Modified: Apr. 23, 2025
-
10.0
HIGHCVE-2001-0808
gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.... Read more
Affected Products : gnatsweb- EPSS Score: %3.10
- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-0946
apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologi... Read more
Affected Products : linux- EPSS Score: %0.04
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0947
Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.... Read more
Affected Products : enterprise_validation_authority- EPSS Score: %0.74
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0950
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of an... Read more
Affected Products : enterprise_validation_authority- EPSS Score: %1.63
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0949
Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) ... Read more
Affected Products : enterprise_validation_authority- EPSS Score: %5.68
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0948
Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which... Read more
Affected Products : enterprise_validation_authority- EPSS Score: %1.82
- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025