Latest CVE Feed
-
7.5
HIGHCVE-2001-0712
The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support s... Read more
Affected Products : internet_explorer- EPSS Score: %9.79
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0535
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variab... Read more
Affected Products : coldfusion_server- EPSS Score: %0.75
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0729
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.... Read more
Affected Products : http_server- EPSS Score: %2.40
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0713
Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the h... Read more
Affected Products : sendmail- EPSS Score: %0.07
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0718
Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.... Read more
- EPSS Score: %16.30
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0505
Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.... Read more
Affected Products : services- EPSS Score: %11.11
- Published: Oct. 30, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0923
RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.... Read more
Affected Products : redhat_package_manager- EPSS Score: %0.07
- Published: Oct. 25, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1462
WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to cause the WebID agent to enter debug mode via a URL containing null characters, which may allow attackers to obtain sensitive information.... Read more
Affected Products : securid- EPSS Score: %0.82
- Published: Oct. 24, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1461
Directory traversal vulnerability in WebID in RSA Security SecurID 5.0 as used by ACE/Agent for Windows, Windows NT and Windows 2000 allows attackers to access restricted resources via URL-encoded (1) /.. or (2) \.. sequences.... Read more
Affected Products : securid- EPSS Score: %0.53
- Published: Oct. 22, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1438
Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruption) by sending a large or crafted SMS image.... Read more
- EPSS Score: %1.04
- Published: Oct. 22, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0736
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.17
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0778
OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).... Read more
Affected Products : omnihttpd- EPSS Score: %3.06
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-0735
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.... Read more
Affected Products : cfingerd- EPSS Score: %0.20
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0757
Cisco 6400 Access Concentrator Node Route Processor 2 (NRP2) 12.1DC card does not properly disable access when a password has not been set for vtys, which allows remote attackers to obtain access via telnet.... Read more
Affected Products : 6400_nrp_2- EPSS Score: %1.77
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0770
Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command.... Read more
Affected Products : guildftpd- EPSS Score: %3.21
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-0765
BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories.... Read more
Affected Products : bison_ftp_server- EPSS Score: %0.08
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0745
Netscape 4.7x allows remote attackers to obtain sensitive information such as the user's login, mailbox location and installation path via Javascript that accesses the mailbox: URL in the document.referrer property.... Read more
Affected Products : messanger- EPSS Score: %1.08
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-0743
Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.... Read more
Affected Products : webboard- EPSS Score: %2.96
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0744
Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.... Read more
Affected Products : imp- EPSS Score: %0.09
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0737
A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack.... Read more
Affected Products : cordless_freedom cordless_freedom_navigator cordless_freedom_pro cordless_itouch_keyboard- EPSS Score: %0.89
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025