Latest CVE Feed
-
5.0
MEDIUMCVE-2001-1156
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.... Read more
Affected Products : typsoft_ftp_server- EPSS Score: %5.88
- Published: Oct. 08, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1128
Buffer overflow in Progress database 8.3D and 9.1C allows local users to execute arbitrary code via long entries in files that are specified by the (1) PROMSGS or (2) PROTERMCAP environment variables.... Read more
Affected Products : progress- EPSS Score: %0.02
- Published: Oct. 08, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1431
Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mod... Read more
- EPSS Score: %0.54
- Published: Oct. 08, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1100
sendmessage.cgi in W3Mail 1.0.2, and possibly other CGI programs, allows remote attackers to execute arbitrary commands via shell metacharacters in any field of the 'Compose Message' page.... Read more
Affected Products : w3mail- EPSS Score: %1.48
- Published: Oct. 07, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1418
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file.... Read more
Affected Products : instant_messenger- EPSS Score: %1.44
- Published: Oct. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1417
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger than the actual image data.... Read more
Affected Products : instant_messenger- EPSS Score: %2.61
- Published: Oct. 06, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1421
AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag.... Read more
Affected Products : instant_messenger- EPSS Score: %2.41
- Published: Oct. 06, 2001
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2001-1125
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.... Read more
Affected Products : liveupdate- EPSS Score: %4.58
- Published: Oct. 05, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1126
Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.... Read more
Affected Products : liveupdate- EPSS Score: %1.15
- Published: Oct. 05, 2001
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2001-1127
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3) _mprshut, (4) orarx, (5) sqlcpp, (6) _probrkr, (7) _sqlschema and (8) _sqldump.... Read more
Affected Products : progress- EPSS Score: %0.01
- Published: Oct. 05, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-0670
Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.... Read more
- EPSS Score: %16.16
- Published: Oct. 03, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1048
AWOL PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.... Read more
Affected Products : awol- EPSS Score: %1.08
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1054
PHPAdsNew PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.... Read more
Affected Products : phpadsnew- EPSS Score: %1.08
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1298
Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.... Read more
Affected Products : webodex- EPSS Score: %0.46
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1299
Zorbat Zorbstats PHP script before 0.9 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.... Read more
Affected Products : zorbstats- EPSS Score: %2.71
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1236
myphpPagetool PHP script 0.4.3-1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the includedir variable.... Read more
Affected Products : myphppagetool- EPSS Score: %2.43
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1051
Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.... Read more
Affected Products : darkportal-unix- EPSS Score: %1.05
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2001-1050
CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.... Read more
Affected Products : ccc- EPSS Score: %0.85
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2001-1419
AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.... Read more
- EPSS Score: %7.13
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2001-1255
WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.... Read more
- EPSS Score: %0.14
- Published: Oct. 02, 2001
- Modified: Apr. 03, 2025